Evidence visual

The minimum privacy file

Four one-page documents that cover most small-firm exposure.

Privacy statement

Plain language, visible to customers, matching what is actually collected.

Data map

What is held, where it lives, who can access it.

Retention rule

When records are deleted, and the discipline of deleting them.

Breach note

Who does what in day one, including the real-risk-of-significant-harm assessment.

Source basis: OPC PIPEDA materials

The Personal Information Protection and Electronic Documents Act does not have a small-business exemption. A ten-person firm holding customer names, emails, payment records, and service histories is handling personal information in the course of commercial activity, which is precisely what the law governs in most provinces, including Ontario for private-sector activity.

The practical question is not whether PIPEDA applies. It is what the smallest defensible compliance posture looks like, and it is smaller than most owners fear.

The four obligations that do the work

First, purpose and consent: know why each category of personal information is collected and be able to show meaningful consent for it. Second, limitation: collect and keep only what the stated purpose needs, and dispose of what is stale. Third, safeguards: protections proportionate to sensitivity, access controls, encryption where appropriate, and care with email and portable devices. Fourth, access and accountability: a named privacy contact and the ability to answer when an individual asks what the firm holds about them.

The Office of the Privacy Commissioner's PIPEDA materials expand each principle, and they are written for exactly this audience.

The minimum privacy file

Four short documents cover most of a small firm's exposure: a plain-language privacy statement customers actually see; an internal data map listing what is collected, where it lives, and who can access it; a retention rule stating when records are deleted; and a breach response note naming who does what in the first day, including the assessment of real risk of significant harm that drives reporting obligations.

None of these needs to exceed a page. Their value is that they exist before the incident, the complaint, or the enterprise customer's security questionnaire arrives.

Where this pays commercially

Privacy posture has become a sales artifact. Larger customers and public-sector buyers increasingly ask vendors for exactly the file described above, and the small firm that produces it in a day looks like a different class of supplier. Pairing the privacy file with baseline cyber controls turns a legal obligation into a procurement asset.

Official sources and programs

Government links used for this briefing

These links point to federal, provincial, territorial, municipal, intergovernmental, or official data sources. Readers should confirm current eligibility and deadlines directly with the issuing government before applying.