Accountability does not transfer with the work
The central principle of Canadian privacy law, for anyone outsourcing work that touches personal data, is that outsourcing the function does not outsource the responsibility. Under the federal Personal Information Protection and Electronic Documents Act, an organisation remains accountable for personal information in its control, including information transferred to a third party for processing, per the Office of the Privacy Commissioner of Canada. Quebec's Law 25 carries the same principle for Quebec residents' data and adds sharper obligations on top.
This reframes the entire diligence exercise. The choice of provider is not only a commercial decision about capability and price. It is a privacy-compliance decision, because the organisation itself remains answerable for what the provider does with the data. A risk team can no longer treat a service provider as a black box whose internals are the provider's business. It has to be able to describe what the provider does with the data, on what basis, and under what controls, because it is the organisation, not the provider, that regulators and data subjects hold to account.
This paper sets out what sound data governance requires when personal data is handled by an outsourced operation under Canadian privacy law. It is organized around the questions a risk committee actually asks, because those questions are the operational form the law takes. It is general information for buyers, not legal advice, and an organisation with Canadian privacy exposure should take its own counsel on its specific obligations.
The two regimes a buyer has to satisfy
Two regimes govern most outsourced work touching Canadian personal data, and a buyer usually has to satisfy both.
PIPEDA is the federal private-sector privacy law. It is built on a set of fair-information principles: accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access and the ability to challenge compliance. For outsourcing, the accountability and safeguards principles do most of the work, because they require the organisation to protect information through comparable contractual and practical measures when a third party processes it.
Quebec's Law 25 is the strictest private-sector privacy regime in Canada, and it applies to the personal information of Quebec residents wherever the handling organisation sits. Its requirements came into force in three annual stages on 22 September 2022, 2023 and 2024. It requires organisations to appoint a person responsible for the protection of personal information, to report confidentiality incidents that present a risk of serious injury and keep an incident register, to conduct privacy-impact assessments including before communicating personal information outside Quebec, to strengthen consent and transparency, and to honour individual rights including access, correction and portability.
The practical consequence for a buyer is that an outsourced arrangement has to be designed to satisfy the stricter of the two regimes on any given point, because a single operation frequently handles data subject to both. Governance built to the Law 25 standard generally clears the PIPEDA bar as well, which is why Quebec exposure tends to set the design baseline.
Residency: where the data lives and what crosses a border
The first governance question is the literal one. Where does the personal data physically reside, what is stored on the provider's systems versus merely accessed in session, and what, if anything, crosses a border.
The distinction between stored and accessed matters because it changes the risk profile. Data that is accessed in session and never persisted on the provider's systems carries different exposure from data held at rest by the provider, and a governance model has to be explicit about which applies to each data element. Vagueness here is itself a finding.
Cross-border flow is where the two regimes bite hardest. Law 25 requires a privacy assessment before personal information is communicated outside Quebec, weighing the sensitivity of the data, the purpose, the protections in place and the legal regime of the destination. That makes the physical location of delivery a documented decision rather than an incidental detail. It also creates a strong structural preference for keeping Canadian data in Canada, because doing so shortens or removes the transfer assessment rather than complicating it. Data held offshore may additionally be reachable by a foreign government under that country's law, regardless of contractual terms, which a Canadian committee handling sensitive data has to weigh. A provider that delivers from Canadian operations and keeps Canadian data in Canada answers the residency question in a sentence, and answers the cross-border question by not raising it.
Access control that can be proven, not just asserted
The second governance question is about people, and it is where many arrangements are weakest. It is not whether access is controlled, but whether the organisation can prove access stays controlled over time.
A sound access model has several components. Role-based access restriction ensures agents see only what their function requires. Session-level logging records who accessed what and when. A documented joiner-mover-leaver process ties access to employment status, so permissions change when roles change. And periodic access recertification reviews existing permissions on a defined cycle and revokes what is no longer needed.
Recertification is the component that most often fails and the one a sharp risk committee probes first, because access granted for a project and never revoked is the most common finding in any access audit. A control that exists on paper but is never reviewed is not a control a committee can rely on. Sound governance therefore specifies not just that access is restricted but how the restriction is verified to persist, with a recertification cycle, an owner and an auditable record. The physical environment supports the logical controls: segregation of the delivery area, device restriction and clean-desk enforcement matter for sensitive work, because a technical access model is undermined by an environment that lets data leave through a phone camera.
Inspection, incidents and individual rights
Three further requirements turn a policy into governance a committee can approve.
Inspection is the one that most often decides the outcome. A right-to-audit clause with on-site inspection, exercisable on reasonable notice, is what separates a verifiable arrangement from an unverifiable assurance. A provider that will not accept inspection is asking the organisation to accept its controls on faith, and the most common reason a risk function blocks an outsourcing proposal is precisely the suspicion that no one will ever go and look. Proximity makes inspection cheap: a Canadian facility can be audited in a day rather than an expedition, which turns the audit right from a theoretical clause into a routine practice.
Incident response has to be rehearsed before it is needed. Law 25 requires reporting of confidentiality incidents that pose a risk of serious injury, so the provider's escalation has to be fast enough for the client to meet its own obligation. Governance specifies a defined notification window measured in hours, named contacts on both sides, and a documented protocol agreed before an incident rather than improvised during one. The provider detects and escalates; the client assesses and reports; both steps have to fit inside the statutory clock.
Individual rights have to be operable through the provider. Under Law 25 and PIPEDA a data subject can request access to, correction of, or in Law 25's case portability of, their personal information. If the provider holds or processes that information, the client needs the provider to be able to locate, produce, correct or delete the relevant record within the statutory timeframe. An operation designed without those workflows cannot support a compliant response, so the ability to action rights requests is a governance requirement, not a nice-to-have.
The structure that makes governance simple, and where Corpshore Canada fits
A pattern runs through every requirement in this paper. Residency is clear when the data stays in Canada. Access is inspectable when the operation is close enough to inspect. The legal footing is familiar when the arrangement sits under PIPEDA and Law 25 rather than an unfamiliar regime. Incident obligations line up when both parties operate under the same Canadian rules. Rights requests are operable when the provider is built to action them. Every one of these resolves more simply under an accountable domestic structure delivering in Canada.
That is not a coincidence, and it is why Canadian delivery, or Canadian governance over a blended arrangement, is so often the structure a risk committee can actually approve. The alternative, an offshore operation under an unfamiliar legal regime that the committee cannot readily inspect, does not fail because its controls are necessarily worse. It fails because the organisation cannot verify them cheaply and cannot answer the five questions above without a long assessment, and unverifiable governance is governance a committee has to decline.
The practical requirements to specify follow from the paper: a named privacy lead within the provider's account team; clear data residency with an explicit stored-versus-accessed distinction; role-based access with periodic recertification; physical segregation and device restriction for sensitive work; session-level logging retained for a defined period; a right to audit with on-site inspection; a documented incident-response protocol with defined notification windows; operable individual-rights workflows; and sub-processor disclosure and approval rights. None of this is exotic. It is the standard a competent provider handling Canadian data should already meet.
Corpshore Canada delivers from Canadian operations under Toronto governance, in compliance with PIPEDA and Quebec's Law 25, bilingually in English and Canadian French, with a control environment built to be inspected rather than described and a ninety-nine point nine per cent uptime record. For a risk committee, the value of that is not a claim. It is that the questions this paper is organized around have short, verifiable answers, and an arrangement that can be verified is an arrangement that gets signed.