Blog OPC Issues New PIPEDA Guidance on Assessing Third-Party Service ProvidersJ. Sébastien A. Gittens, Suzie Suliman, Kees de Ridder, Stephen D. Burns and Ruth E. Promislow September 14, 2026 ![]() Authors J. Sébastien A. GittensTech & Data, National Practice Group Leader Suzie SulimanAssociate, Trademark Agent Kees de RidderPartner, Patent Agent, Trademark Agent Stephen D. BurnsPartner, Trademark Agent Ruth E. PromislowPartner On September 10, 2026, the Office of the Privacy Commissioner of Canada (OPC) released draft guidance aimed at helping organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) assess the privacy practices of prospective third-party service providers before procuring products, services or technologies that involve the collection, use or disclosure of personal information. The OPC is accepting comments until December 4, 2026, and may revise the guidance thereafter. In the meantime, the guidance underscores a clear message from the OPC: privacy due diligence is not a perfunctory procurement exercise; it is a core component of an organization's accountability obligations. Accountability Remains at the CentrePrinciple 4.1.3 of PIPEDA: (i) provides that organizations remain "… responsible for personal information in [their] possession or custody, including information that has been transferred to a third party for processing;" and (ii) requires organizations to "… use contractual or other means to provide a comparable level of protection while the personal information is being processed by a third party." Building on the foregoing accountability requirements, the guidance outlines a series of best practices designed to assist organizations in evaluating prospective service providers before obtaining a product, service or technology. Importantly, the OPC notes that an organization should ensure that those responsible for carrying out any such assessments have the appropriate training and expertise to do so effectively. Best PracticesThe following is a summary of the key best practices identified in the guidance. 1. Know What Personal Information Is InvolvedOrganizations should initially determine what personal information will be collected, used or disclosed in the proposed use of the product, service or technology. The OPC specifically advises organizations to:
Understanding the personal information involved is critical to assessing the sufficiency of a third-party provider's privacy posture. 2. Map Data FlowsThe guidance recommends that organizations establish a map showing how personal information moves between the organization, individuals whose information is involved, the service provider and any other entities involved in providing the product, service or technology. Organizations should also understand where data are stored, including on cloud infrastructure operated by the provider or its subcontractors. 3. Confirm How Data Will Be UsedThe guidance recommends confirming each purpose for which a provider will collect, use or disclose personal information on the organization's behalf. Importantly, organizations should determine whether the provider intends to use personal information for its own purposes, including training its algorithms or improving its internal processes. Where such uses are contemplated, organizations should assess whether the proposed use is consistent with PIPEDA and other applicable privacy laws, whether additional consent is required from individuals and whether changes need to be made to the organization's privacy policies if the third-party offering is adopted. 4. Understand Functionality and PerformanceThe guidance recommends organizations evaluate whether technologies present known risks, including systemic bias, security vulnerabilities and factors that may lead to inaccuracies or discriminatory treatment. Notably, the guidance encourages organizations to develop a sufficient understanding of any technology they intend to procure and, where necessary, to seek additional information from the service provider and consult independent third-party sources regarding the technology's performance. This expectation may potentially prove challenging in the context of certain AI-driven products and services, particularly where the underlying models or decision-making processes operate as a "black box" and offer limited transparency into how outputs are generated. 5. Confirm Roles and ResponsibilitiesThe OPC recommends that organizations understand whether subcontractors will have access to personal information and identify those subcontractors in writing. Organizations should also ensure that subcontractors are subject to privacy protections equivalent to those imposed on the primary service provider. This is a notable reminder that accountability obligations extend throughout the vendor ecosystem and not merely to the first-party contractor. 6. Assess Out-of-Country Collection and TransfersThe guidance reiterates that organizations should identify the jurisdictions where personal information will be collected, used, disclosed and stored. Where information is processed outside Canada, organizations are expected to assess risks relating to integrity, security and confidentiality of personal information. 7. Identify the Source of Training DataThe guidance contains a dedicated section addressing training data. If a service provider's technology relies on training data, organizations are expected to conduct due diligence to ensure the sourcing is consistent with PIPEDA. This could involve asking the provider where the training data originated, how such data were collected, and whether the collection and use of such data complied with applicable privacy laws. This is one of the guidance’s AI-specific provisions and suggests a growing OPC focus on the data used to develop machine learning systems. 8. Verify Security Practices and Administrative ControlsThe OPC continues to emphasize an obligation to confirm the security policies and practices employed to safeguard personal information, including cybersecurity, physical access and work environment controls. The guidance particularly flags the need to (i) identify security features that are built into the design of the product or technology, and (ii) confirm who is responsible for managing those settings. Organizations should ensure that their agreements clearly address how data breaches and security incidents will be managed, including the allocation of responsibilities among the organization, the service provider and any subcontractors. This should include responsibilities for incident response, investigation, notification, remediation and compliance with applicable breach reporting requirements. 9. Assess the Risk of Vendor Lock-In and Lock-OutInterestingly, the guidance highlights the need to assess the risks of:
These considerations are not traditionally viewed as privacy-specific issues. Their inclusion suggests the OPC increasingly views operational resilience and business continuity as integral to responsible information governance. 10. Confirm Data Retention and End of Contract ProceduresThe guidance includes expectations for organizations to verify the provider's procedures for securely destroying personal information at the end of its lifecycle, including data on cloud servers, backups and with subcontractors. Additionally, organizations are expected to understand how personal information is managed when the provider's services are terminated, including its return to the organization and methods of deletion for the remaining information. In practice, this suggests that organizations are expected to negotiate data-return and destruction provisions in their vendor agreements, including clear timelines and certification requirements. 11. Identify Monitoring MechanismsFinally, the OPC makes clear that accountability does not end at contract signing. Organizations should consider mechanisms to monitor and assess providers on an ongoing basis, including the use of access logs, reporting tools, regular testing and independent audits. This reinforces a recurring theme in modern privacy regulation: accountability is a continuous obligation rather than a one-time exercise. Key TakeawaysThe OPC's draft guidance outlines the factors organizations should consider when conducting privacy due diligence on prospective third-party service providers to satisfy their accountability obligations under PIPEDA. Although framed as a series of best practices rather than mandatory requirements, the guidance provides valuable insight into the standards the OPC may apply when assessing an organization's compliance with legal obligations. It should also be noted that Bill C-36 is anticipated to repeal the current federal private sector privacy regime under PIPEDA and replace it with An Act to enact the Protecting Privacy and Consumer Data Act. By releasing the draft Guidance at this stage, the OPC appears to be signaling its expectation that organizations begin adopting enhanced privacy governance and accountability practices now, rather than waiting for the new legislative framework to come into force. How Bennett Jones Can HelpAs above, organizations are encouraged to provide comments to the OPC with respect to the guidance by December 4, 2026. Bennett Jones' Privacy and Data Protection group is available to assist your organization to do so and answer any questions you might have about this document as well as your organization’s privacy obligations in Canada. Republication Requests To obtain permission to republish this publication or any other publication, contact Erica Wirthlin at wirthline@bennettjones.com. For Informational Purposes Only This publication provides an overview of trends and legal updates for informational purposes only. For personalized legal advice, please contact the authors. AuthorsJ. Sébastien A. Gittens, Tech & Data, National Practice Group Leader Calgary • 403.298.3409 • gittenss@bennettjones.com Suzie Suliman, Associate, Trademark Agent Toronto • 416.777.6532 • sulimans@bennettjones.com Kees de Ridder, Partner, Patent Agent, Trademark Agent Calgary • 403.298.3122 • deridderk@bennettjones.com Stephen D. Burns, Partner, Trademark Agent Calgary • 403.298.3050 • burnss@bennettjones.com Ruth E. Promislow, Partner Toronto • 416.777.4688 • promislowr@bennettjones.com |
