Language selection

Search

Guidance on assessing third-party service providers

Notice

The Office of the Privacy Commissioner of Canada is accepting comments on this document until December 4, 2026, at which time we will evaluate whether any amendments are required. Should changes be made at that time, the document will be updated and a link to a summary of any edits will be included. Comments can be sent by email to cpvp-opcconsultation1@priv.gc.ca.

What is the purpose of this guidance?

This guidance is meant to help organizations assess a third-party service provider’s approach to privacy protection before working with them. Third party assessment is a key due diligence measure that can help organizations meet their accountability obligations under PIPEDA.

Who is this guidance for?

This guidance is for organizations subject to PIPEDA that are interested in working with a third-party service provider to implement a product, service, or technology that involves the collection, use, or disclosure of personal information.

This includes circumstances where an organization:

  • Uses a product, service, or technology provided by a third party to handle personal information under their control;
  • Integrates a third party’s technology into a product or service of their own that handles personal information;
  • Outsources collection, use or disclosure of personal information to a third party; or
  • Transfers personal information to a third party for processing.

What does this guidance cover?

This guidance outlines a set of best practices for assessing a third party’s approach to privacy protection. When combined with other measures, these practices can help organizations to meet their Accountability obligations under Principle 4.1.3 of PIPEDA.

This guidance does not cover all requirements that may apply under PIPEDA when an organization works with a third party. For more information, organizations can consult the OPC’s guidance on Outsourcing for businesses and Interpretation Bulletin on Accountability.

Key points

  • Organizations are responsible for personal information under their control. This includes personal information that is collected by a third party on their behalf or transferred to a third party for processing.
  • Organizations must ensure comparable protection for personal information that is collected, used, or disclosed on their behalf by a third party.
  • Organizations should assess a third party’s privacy practices before obtaining products, services, or technology that involves the collection, use, or disclosure of personal information.
  • Conducting a rigorous assessment based on best practices can help organizations to meet their accountability obligations under PIPEDA.

Guidance

Under PIPEDA Principle 4.1.3, organizations are responsible for personal information in their possession or custody, including information that has been transferred to a third party for processing. Personal information is generally considered to be in the custody of an organization when an organization has control over its collection, use, or disclosure.

This means that organizations are responsible for personal information that is collected, used, or disclosed on their behalf when they work with a third party.

Principle 4.1.3 also requires organizations to use contractual or other means to ensure comparable protection for personal information while it is being processed by a third party.

Third party assessment

Assessing a third-party service provider’s approach to data protection before deciding to work with them can help organizations to ensure that they meet their obligations under Principle 4.1.3.

Third party assessment helps to:

  • Identify privacy and compliance risks, and inform strategies for mitigating those risks;
  • Make decisions about whether to work with a third-party service provider;
  • Inform terms of a contractual agreement with a third party;
  • Demonstrate accountability to oversight bodies;
  • Carry out responsible privacy practices.

Organizations should assess a third party’s privacy practices before using, or entering into an agreement to obtain, a prospective provider’s services.

They should also ensure that the individual(s) responsible for carrying out the assessment have the appropriate training and expertise to do so effectively. In some cases, it may be necessary to secure external expertise (for example, external legal counsel or technical expertise) to address gaps in knowledge or experience.

While third-party assessment is a recommended practice to help organizations meet their obligations under Principle 4.1.3, organizations that work with third parties have further obligations under PIPEDA as well. Organizations are ultimately responsible for ensuring that their use of a provider’s product, service, or technology complies with all applicable privacy requirements under PIPEDA.

Best practices for assessing third-party service providers

The best practices outlined below are intended to help organizations carry out an assessment of a third party’s approach to privacy. They do not necessarily address all considerations that may relate to an organization’s assessment of a third-party service provider, which may vary from case to case. Rather, they provide a general resource that organizations can draw from to help develop and carry out their assessment.

Know what personal information is involved

  • Knowing what personal information will be collected, used, or disclosed in the proposed use of the product, service, or technology can help to identify what personal information is under your control and the privacy risks involved. Be sure to consider personal information that your organization will process as well as any personal information that the third-party service provider will collect or process on your behalf, including information that your organization may share with them.
  • Identify whether any of the personal information involved is sensitive personal information. This generally includes information such as health and financial data, ethnic and racial origins, political opinions, genetic data, neural data, uniquely identifying biometric data, an individual’s sex life or sexual orientation, and religious or philosophical beliefs. For further details about what information is considered sensitive, see the OPC’s Interpretation Bulletin on Sensitive Information.
  • Use extra scrutiny where products, services, and technologies involve the collection or use of publicly available information. PIPEDA still applies to personal information that is accessible in public spaces, including information posted online, and exceptions to privacy requirements for publicly available personal information are limited. See the OPC’s Interpretation Bulletin on Publicly Available Information for more details.
  • Use extra scrutiny where a third-party service provider claims that the information involved is anonymized. Even when datasets do not directly identify individuals, they may still contain personal information that could be re-identified. Be sure to request specific information from the service provider about the anonymization techniques being used and how they meet applicable legal thresholds.

Map data flows

  • Establish a map of how personal information flows between your organization, your clients and any other individuals, the third-party service provider, and any additional parties involved in providing the product, service, or technology. Include any flows of personal information between the provider and any subcontractors, as well as any sources of data from which the provider collects personal information on your behalf. Be sure to account for any transfers of personal information to locations where it is stored, for example cloud storage databases controlled by the provider or another third party.

Confirm how data will be used

  • Confirm each purpose for which the provider will collect, use, or disclose personal information on your behalf. If the provider intends to use any of the personal information for their own purposes (for example, to train an algorithm or to improve internal processes), assess whether consent is required for them to do so, and whether this purpose is consistent with PIPEDA and other applicable privacy laws.

Understand functionality and performance

  • Be aware of how the provider will treat personal information and whether there are known risks in the technology’s functionality, such as systemic bias, security vulnerabilities, or factors that may lead to inaccuracy or discriminatory treatment. Verify what measures the provider has taken to reduce these risks.
  • Assess your core requirements for the product, service, or technology based on your purposes for collecting, using, or disclosing personal information, and ensure that additional functionalities can be disabled if they are not required or are outside the scope of your needs.
  • If you are unsure of how the technology involved works, request additional materials as needed. Consider also consulting independent external resources providing insight into the technology’s performance.
  • Assess how personal information is stored and retrieved for auditing purposes and for responding to individual access requests.

Confirm roles and responsibilities

  • Confirm with the provider whether any personal information will be handled by a subcontractor. If so, establish the identities of the subcontractor(s) in writing and confirm that they will be held to the same standards for privacy protection as the provider.
  • Identify the roles and responsibilities of your organization, the provider, and any subcontractors with respect to personal information collected, used, or disclosed on your behalf or transferred to the provider, in light of the considerations outlined in this document.
  • Determine how your organization and the provider will handle access requests from individuals concerning their personal information.
  • Confirm in a contract the provider’s understanding of their roles and responsibilities and of their obligations under PIPEDA. Consider including best practices outlined in this document as contractual provisions in the agreement.

Assess out-of-country collection and transfers

  • If the provider or a subcontractor will collect, use, or disclose personal information on your behalf, identify the jurisdictions in which those actions would take place. Be sure to understand what your legal obligations are under PIPEDA with respect to any personal information collected on your behalf in another jurisdiction or transferred from your organization to another jurisdiction.
  • Assess the risks that could jeopardize the integrity, security, and confidentiality of personal information when it is transferred to a third-party service provider operating outside of Canada. See the OPC’s Guidelines for processing personal data across borders for further information.

Identify the source of training data

  • Confirm whether the provider’s technology relies on the use of training data, for example, to train an AI algorithm or test its functioning. If it does, request information about the source of the data and how the provider collected it. Consider whether this sourcing is consistent with legal requirements under PIPEDA and/or the jurisdictions in which it was collected.

Verify security practices and administrative controls

  • Confirm what security policies and practices the provider has in place to ensure that personal information processed using their product, service, or technology is properly safeguarded at all times. This can include cybersecurity and physical access controls as well as work environment controls.
  • Be aware of security features that are built into the design of the product or technology, including optional security settings that can be enabled or disabled, and confirm who is responsible for managing those settings.
  • Confirm how a data breach will be managed, including the roles and responsibilities of your organization, the provider, and any subcontractors. For further information about obligations in the event of a data breach, see the OPC’s guidance on breach reporting.

Assess the risk of vendor lock-in and lock-out

  • Assess the risk of becoming technologically dependent on a provider’s proprietary technology or product (“vendor lock-in"). Vendor lock-in can reduce your organization’s control over personal information processing and can make it more difficult to switch providers in the event of unsatisfactory performance. Consider factors such as the use of proprietary data formats, and possible mitigation measures such as contractual guarantees for data portability.
  • Assess the risk of the provider ceasing operations (“vendor lock-out"). Vendor lock-out can create concerns around access and recovery of personal information held by the provider. Consider factors such as the provider’s longevity and supply-chain dependence, and regulatory constraints relevant to their operating environment.

Confirm data retention and end of contract procedures

  • Confirm the provider’s practices for destroying personal information at the end of its lifecycle, including information stored on cloud servers, backups, and information held by any subcontractors.
  • Confirm what happens to personal information held by the provider or any subcontractors once the provider’s services are terminated, including how any personal information is transferred back to your organization, the methods of deletion for any remaining personal information, and how it is disposed of. For further information about retention and disposal requirements under PIPEDA, see the OPC’s guidance on Personal Information Retention and Disposal.

Identify monitoring mechanisms

  • Consider how the performance and security of the provider’s technology can be monitored and assessed once it is implemented. This can include the use of access logs, reporting tools, regular testing, and independent audits.
  • Consider also how the provider’s compliance with privacy obligations can be monitored, on an ongoing basis, with respect to any personal information they process on your behalf, for example through inspections or independent audits.
Date modified: