RIGHTS • LIBERTIES • INSTITUTIONS
Liberty Journal

Examine the principles. Follow the consequences.

Privacy / Analysis · Canada

Outsourced data still needs an accountability trail

New Canadian guidance addresses vendor assessment before a service is adopted. A completed questionnaire and responsibility for the resulting data use are not the same thing.

AI-assisted desk article · Automatically published after automated checks. No individual human review.

The Office of the Privacy Commissioner of Canada published guidance on assessing third-party service providers on September 10, 2026. It addresses a question that can disappear behind a procurement decision: what happens to accountability when another company handles personal information? The publication announcement says organizations remain responsible for information under their control, including information transferred for processing or collected on their behalf.

The practical distinction is between choosing a supplier and explaining a data flow. A supplier's suitability concerns what that supplier can do. Accountability also concerns what the purchasing organization asks it to do, which information is involved, and how the arrangement relates to the organization's own activities. A procurement approval cannot answer all of those questions merely by existing.

The assessment is not the service

Imagine a fictional booking business evaluating a messaging provider. Its procurement file contains a signed questionnaire, but its application sends the provider both an appointment time and a free-text note. A reviewer could establish that a questionnaire was completed without establishing that the assessment considered the note. This is a hypothetical illustration of a mismatch between documentation and actual information, not a reported incident.

The example also separates two possible questions. Did the assessment examine the intended information flow? Does the implemented flow match that description? Answering the first does not logically answer the second. Comparing them requires a connection between the assessment's assumptions and the service that was eventually put into use.

The OPC's detailed guidance recommends assessment before obtaining services or entering an agreement. It covers outsourced activities, integrated third-party technology and information transferred for processing. The document describes best practices that can help meet accountability obligations when combined with other measures; it expressly does not cover every PIPEDA requirement that might apply.

That qualification prevents a second category error: treating the guidance as a certification scheme. The fact that an organization considered the listed issues would not, on its own, establish that every use of a provider was compliant. Equally, the document's focus on assessment does not establish that outsourcing itself is prohibited. The relevant activity and allocation of responsibilities still matter.

A contract and a technical description also perform different explanatory jobs. In the fictional example, the contract could say who is expected to delete a note. A system description could explain where the note is stored. Neither statement alone would demonstrate that deletion happened. An accountability trail links such claims to the evidence capable of testing them rather than treating several documents as interchangeable assurances.

The OPC is accepting comments on the guidance until December 4, 2026, and says it will assess whether amendments are needed. That invitation is a consultation about the document, not an announced suspension of existing accountability obligations.

Both sources express the regulator's position; they are not a survey of vendor performance or evidence about a particular business. The new publication gives readers a way to distinguish an assessment exercise from the activity being assessed. Whether any real arrangement provides the required protection remains a question about that arrangement, not its paperwork alone.