Canadian Privacy Commissioner Issues Draft Guidance on Third-Party Service Providers

Canada
Sep 10, 20261 sources
  • 01The OPC published PIPEDA guidance on assessing third-party service providers on September 10, 2026.
  • 02The guidance aims to help businesses manage privacy and compliance risks when providers process personal information for them.
  • 03It covers provider due diligence, contractual terms, and the organization’s accountability for outsourced processing.
  • 04Businesses using vendors that handle personal information may need to review their assessment processes and service-provider contracts.
  • 05The OPC will accept comments on the guidance until December 4, 2026.

The Office of the Privacy Commissioner of Canada (OPC) has released guidance for businesses that use third-party service providers under the Personal Information Protection and Electronic Documents Act (PIPEDA). The guidance was published on September 10, 2026, and the OPC is accepting comments until December 4, 2026.

The guidance is intended to help organizations assess privacy and compliance risks when a vendor, contractor, cloud provider, or other service provider handles personal information on their behalf. It addresses due diligence before engaging a provider, contractual protections, and the organization’s continuing accountability for personal information processed by the provider.

For businesses, the guidance reinforces that outsourcing data processing does not remove PIPEDA responsibilities. Organizations should be able to evaluate a provider’s privacy practices and use contracts that set appropriate requirements for handling, safeguarding, and managing personal information.

Companies that rely on third parties to process customer, employee, or other personal data may wish to review vendor-selection processes, privacy assessments, and existing service-provider agreements against the OPC’s approach. The guidance remains open for stakeholder feedback until December 4, 2026.

Sources (1)

priv.gc.caSep 10, 2026

Canadian Privacy Commissioner Issues Draft Guidance on Third-Party Service Providers