Canada’s Privacy Commissioner, Philippe Dufresne, has submitted formal recommendations to the President of the Treasury Board on modernizing the federal Privacy Act — the law governing how the federal public sector handles personal information. Commissioner Dufresne expressed support for recognizing privacy as a fundamental right, updating federal public-sector privacy principles, and introducing mandatory breach notification and reporting obligations. He also recommended stronger enforcement mechanisms and legislative requirements for privacy impact assessments in high-risk activities. For private-sector Canadian business owners, the honest summary is this: these proposals concern federal government institutions, not your business directly. But the direction they signal — stronger rights, mandatory breach reporting, and greater scrutiny of how personal data is processed — is worth understanding before rules shift closer to you.
What This Means for Canadian Business Owners
The federal Privacy Act applies to federal government departments and agencies — not to private Ontario businesses, trades contractors, or professional services firms. The legislation that governs how most private-sector Canadian businesses handle personal information is the Personal Information Protection and Electronic Documents Act (PIPEDA), along with provincial equivalents. So a direct, honest reading of this development is: the Privacy Commissioner’s submission does not change your legal obligations today.
What it does signal is a regulatory posture. Canada’s federal privacy regulator is actively pushing for stronger enforcement authority, mandatory privacy impact assessments for high-risk activities, and increased transparency requirements around how personal data is processed — particularly where systems are involved in decisions affecting individuals. That posture has historically influenced how PIPEDA enforcement is interpreted and how future private-sector legislation gets framed. If you handle employee records, client financial data, or sensitive personal information — and most businesses do — the direction of travel in Canadian privacy law matters.
It is also worth being precise about what the Commissioner did not say. He did not declare that private-sector businesses must immediately change their data practices. He did not introduce new penalties for small businesses. He did not require Canadian data hosting. PIPEDA does not require that Canadian businesses store data exclusively on Canadian servers — that is a common misconception that persists despite being factually incorrect under current law. What PIPEDA requires is reasonable safeguards appropriate to the sensitivity of the data.
The Real Problem with Privacy Compliance for Small Business
Most small and mid-sized Canadian businesses are not indifferent to privacy — they are overwhelmed by competing demands and genuinely uncertain about where the line is. The problem is not bad faith; it is that the compliance landscape is fragmented and the guidance is often written for large institutions with dedicated legal teams.
The practical risk for a typical Ontario business is not a dramatic Privacy Commissioner investigation. It is smaller and more operational: a data breach that goes unreported because the business owner did not know reporting was required under PIPEDA, or employee payroll records stored in an email thread because no one set up a secure process, or a cloud software subscription held in the owner’s personal Gmail account with no access controls. These are the everyday vulnerabilities that privacy modernization is designed to address — and that enforcement attention, when it does arrive, will look for.
The Commissioner’s push for mandatory privacy impact assessments for high-risk activities is notable here. Right now, a PIA is a recommended practice, not a legal requirement for most private-sector businesses. If similar obligations migrate into PIPEDA reform — which is a separate, ongoing process — businesses that handle sensitive personal or financial information would face a more structured compliance burden than they do today.
For businesses working with a bookkeeper, payroll provider, or financial records service, the relevant question is: do you know where your data is, who can access it, and what happens if that relationship ends? These are reasonable questions to ask of any service provider, including us. You can review how TBR approaches data handling and engagement scope before any work begins.
What Clean Privacy Practice Looks Like in Practice
The following is a representative scenario, not a documented client case study. Details are illustrative of the kind of operational decisions that arise in small business privacy practice.
Consider a typical professional services business in Ontario — a consulting firm or a trades operation — where the owner handles invoicing, payroll, and client records across a combination of cloud software, email, and a shared drive. In a representative engagement with TBR, the first practical step is confirming which software holds which data: QuickBooks Online, Xero, or Wave for financial records; a separate payroll system if applicable; and a file-sharing arrangement for year-end documents.
In many firms like this, the goal during onboarding is to close the obvious gaps — shared login credentials, uncontrolled access to bank feeds, and financial documents stored without version control or access logging. None of this is dramatic. It is the operational hygiene that reduces risk before an incident occurs. When the Commissioner’s submission calls for “safeguards and the management, notification, and reporting of privacy breaches” to become a legal obligation, this is the kind of ground-level practice that obligation would touch.
A representative bookkeeping engagement at TBR does not replace a formal privacy compliance program. What it does is ensure that financial records are organized, access-controlled within the software platform, and handled under an engagement agreement that is transparent about scope, data access, and what happens when the relationship ends. That is a starting point, not a complete privacy framework.
How to Know If Your Business Is Ready
You do not need to be a privacy lawyer to take a useful first pass at your exposure. Four practical questions cover most of the ground that a regulator — or a data breach — will surface first:
- Do you know what personal information your business holds and where it lives? Employee SINs, client contact records, payroll data, and financial account credentials are all personal information under PIPEDA. If you cannot answer this in two minutes, that is the first gap.
- Do you have a process for a data breach — even a small one? Under PIPEDA, breaches that pose a real risk of significant harm must be reported to the Privacy Commissioner and the affected individuals. An owner who does not know this requirement exists cannot meet it.
- Who has access to your financial software, and has that list been reviewed in the past year? Former employees, legacy accountants, or onboarding errors can leave access open longer than intended.
- Does your bookkeeper, payroll provider, or accountant operate under a written agreement that addresses data access and disposal? If not, that is worth correcting before privacy obligations tighten further.
If the answer to any of these is “I’m not sure,” you are not alone — and the regulatory direction the Commissioner is advocating suggests that “not sure” will become a less defensible position over time.
Frequently Asked Questions
Does the Privacy Commissioner’s submission change PIPEDA obligations for my Ontario business?
No — not directly and not yet. Commissioner Dufresne’s submission addresses modernization of the federal Privacy Act, which governs federal public-sector institutions, not private-sector businesses. PIPEDA governs most private-sector Canadian businesses. The submission does not amend PIPEDA. However, the regulatory direction it signals — mandatory breach notification, mandatory privacy impact assessments for high-risk activities, and stronger enforcement — is consistent with where federal privacy reform for the private sector has been moving.
Does Canadian law require me to store client or employee data on Canadian servers?
No. PIPEDA does not require Canadian data residency. What it requires is that organizations use contractual or other means to provide comparable protection when transferring personal information to third parties, including across borders. The misconception that Canadian hosting is legally required is widespread but incorrect under current law. If this is relevant to a software or cloud platform decision, it is worth verifying against the current PIPEDA guidance at the Office of the Privacy Commissioner’s website.
What are my obligations if my business experiences a data breach?
Under PIPEDA’s breach of security safeguards rules, businesses must report a breach to the Privacy Commissioner if it poses a real risk of significant harm to an individual, notify affected individuals, and keep records of all breaches. These obligations are already in force for private-sector businesses. The Commissioner’s submission advocates for parallel obligations to be introduced in the federal Privacy Act for public-sector institutions — but the private-sector obligation exists now.
What does TBR’s data handling look like for bookkeeping clients?
TBR operates under PIPEDA-aware Canadian data handling practices. Client financial records are managed within the agreed software platform — QuickBooks Online, Xero, or Wave — and access is limited to the scope of the engagement. Scope and data access terms are confirmed before work begins. TBR does not hold client data beyond the engagement without explicit agreement. You can review the approach to data handling at trustedbr.ca/pipeda.
Should I be doing a formal privacy impact assessment for my small business?
Under current PIPEDA, a privacy impact assessment is a recommended practice, not a legal requirement for most private-sector businesses. However, the Commissioner’s submission advocates for legislative requirements to conduct PIAs for high-risk activities, and similar proposals are active in broader federal privacy reform discussions. For a small Ontario business handling employee payroll data, client financial records, or sensitive personal information, a basic internal review of what data you hold, who accesses it, and what your breach response looks like is a practical and proportionate starting point — even without a legal mandate. A formal PIA may become more relevant if reform moves forward.
Alex Cameron, who founded TBR after working as a CRA Trust Account Examination Officer, built this practice around the principle that business owners should understand exactly what is being done with their records and why — whether the subject is tax filings, year-end preparation, or data access during a bookkeeping engagement. Privacy is part of that.
If this resonates with how your business operates, book a free 30-minute consultation. We’ll review your current bookkeeping situation and give you a clear quote — no commitment required.