PIPEDA for accounting firms: a working compliance checklist
What PIPEDA requires of firms holding client financial data — consent, safeguards, breach response, retention — plus Quebec's Law 25 and provincial overlays.
This is a working checklist, not legal advice. PIPEDA applies to organisations that collect, use or disclose personal information in the course of commercial activity — which includes essentially every accounting practice in Canada outside the provinces with substantially similar legislation.
1. Accountability
Name someone accountable for privacy compliance. In a small firm this is a partner, and the appointment should be written down somewhere other than in that partner's head.
2. Consent and purpose
Identify why you collect each category of personal information before you collect it, and limit collection to what those purposes require. Engagement letters are the natural home for this: the letter that defines the scope of work can also define the scope of data.
3. Safeguards proportional to sensitivity
Financial and tax data sits at the sensitive end, so the expected safeguards are correspondingly higher:
- Encryption in transit and at rest.
- Access control — staff see the clients they work on, not the whole book, unless their role requires it.
- Multi-factor authentication on every account with access to client data.
- An audit trail showing who accessed or changed what.
- A documented, tested restore — a backup nobody has restored is a hypothesis.
4. Retention and disposal
Set retention periods per record type — professional standards and tax law set floors, PIPEDA sets the expectation of a ceiling — and dispose securely when they expire. "We keep everything forever" is a defensible answer to an auditor and an indefensible one to a regulator.
5. Breach response
Breaches posing a real risk of significant harm must be reported to the Privacy Commissioner and to affected individuals, and you must keep records of all breaches — including the ones that do not meet the reporting threshold.
Write the response plan before you need it: who is called, who assesses risk of harm, who notifies, and where the log lives.
6. Provincial overlays
Alberta, British Columbia and Quebec have their own private-sector privacy legislation. Quebec's Law 25 is the most demanding: mandatory privacy officer, breach register, privacy impact assessments for systems handling personal information, and rules around transfers outside Quebec.
A firm with clients in multiple provinces should plan to the strictest applicable standard rather than maintaining several.
7. Vendors are in scope
You remain accountable for personal information transferred to a service provider. Ask where the data is hosted, what the provider's breach obligations are, whether tenant isolation is enforced at the database layer, and what happens to your data when the contract ends.
"Hosted in Canada" is not a legal requirement under PIPEDA, but it removes an entire category of client question and cross-border assessment.