Skip to content
Corpshore Canada

Why Corpshore

Security and compliance

A serious buyer checks the compliance posture before anything else. This page sets out the Canadian privacy, marketing and accessibility regimes an engagement may touch, what each requires, how we work within it and the documentation you can ask us for.

Canadian delivery operates under PIPEDA by default and Quebec Law 25 for Quebec work, with provincial privacy laws in Alberta and British Columbia, Ontario PHIPA for health data, CASL for commercial messaging, AODA and the Accessible Canada Act for accessibility, and GDPR where EU personal data is in scope. For each we state what it requires, how we work within it and what documentation you can request.

How to read this page

Compliance is not a badge, it is a set of specific obligations that apply depending on the data, the province and the customers involved. The regimes below are the ones a Canadian engagement most often touches. For each we set out three things in plain terms: what the law or standard requires, how Corpshore works within it, and the documentation you can request during due diligence. PIPEDA and Quebec Law 25 are the two we operate under by default. The others apply according to scope, and we confirm which are engaged for your work rather than claim all of them by reflex.

A note on what we do not claim. We describe our posture in terms of governance and process, such as role-based access, purpose limitation, documented safeguards and contractual commitments, rather than certifications we cannot substantiate on this page. Where an engagement requires a specific attestation or audit, that is addressed directly in the contract and its schedules. This page is general information about the frameworks, not legal advice, and your own counsel should review any compliance commitment before you rely on it.

What you can always request

Across every regime, the pattern is the same. You can ask for the data processing terms, a description of the safeguards and access controls, the cross-border transfer position for your engagement, the breach notification process and the roles accountable for compliance on the account. We would rather document the position before go-live than have it surface during an audit. The regime-by-regime detail below tells you what is specific to each framework.

The regimes, one by one

PIPEDA

Personal Information Protection and Electronic Documents Act

Canada's federal private-sector privacy law, the default baseline for commercial personal data.

What it requires
Consent for collection, use and disclosure, limiting data to identified purposes, safeguards proportionate to sensitivity, accuracy, individual access rights, accountability for information handled by a service provider, and reporting of breaches that pose real risk of significant harm.
How we work within it
Canadian delivery operates under PIPEDA by default. Access is role-based and limited to the data a task requires, work is performed within your platforms and governance, the cross-border position is documented before go-live, and accountability for personal information stays with the operation holding your relationship.
What you can request
You can request the data processing terms, the description of safeguards and access controls, the cross-border transfer position for your engagement, the breach notification process and the roles responsible for privacy on the account.

Quebec Law 25

Quebec Act respecting the protection of personal information (Law 25)

Quebec's private-sector privacy law, the most demanding in the country, for Quebec engagements.

What it requires
Strengthened consent, a designated person responsible for privacy, privacy impact assessments in defined circumstances, tighter breach notification, governance policies, and specific obligations around automated decision making and the transfer of information outside Quebec.
How we work within it
Quebec-facing work is designed to meet Law 25 rather than retrofitted to it. Where the law applies we apply its consent, assessment and notification obligations, and Quebec engagement data can be kept in Quebec where you require it, with the transfer position documented.
What you can request
You can request the Law 25 posture for your engagement, the approach to privacy impact assessments where triggered, the breach notification commitments, and the data residency arrangement for Quebec work.

Alberta PIPA

Alberta Personal Information Protection Act

Alberta's private-sector privacy law, relevant to Alberta delivery and Alberta personal data.

What it requires
Consent for the collection, use and disclosure of personal information by private-sector organisations, reasonable safeguards, purpose limitation, access and correction rights, and breach notification to the Alberta Commissioner where there is a real risk of significant harm.
How we work within it
Alberta delivery applies the same governed practices as the rest of the Canadian operation: role-based access, purpose-limited handling and documented safeguards, aligned to PIPA where Alberta personal data is in scope.
What you can request
You can request the safeguards description, the access and correction handling, and the breach notification approach as they apply to Alberta-delivered work.

BC PIPA

British Columbia Personal Information Protection Act

British Columbia's private-sector privacy law, relevant where BC personal data is handled.

What it requires
Consent, limited and reasonable collection, use and disclosure, safeguards appropriate to sensitivity, access and correction rights, and accountability for personal information under an organisation's control.
How we work within it
Where British Columbia personal data is in scope, handling is aligned to BC PIPA through the same governance model of purpose limitation, role-based access and documented safeguards used across Canadian delivery.
What you can request
You can request the applicable safeguards, the access and correction process, and confirmation of how BC personal data is handled within the engagement.

Ontario PHIPA

Ontario Personal Health Information Protection Act

Ontario's health privacy law, relevant where personal health information is processed.

What it requires
Rules for the collection, use and disclosure of personal health information, the concept of a health information custodian and its agents, strong safeguards, limits on use to the minimum necessary, and notification of privacy breaches.
How we work within it
For work involving personal health information in Ontario, delivery is scoped to act within the custodian relationship you define, on a minimum-necessary basis, with safeguards and access controls set out in the engagement rather than assumed.
What you can request
You can request the agent-of-custodian arrangement, the minimum-necessary handling scope, the safeguards applied and the breach notification commitments for health information.

CASL

Canada's Anti-Spam Legislation

Federal law governing commercial electronic messages, relevant to outreach and marketing support.

What it requires
Consent before sending commercial electronic messages, clear sender identification, a functioning unsubscribe mechanism, and record keeping to demonstrate consent, with limited exceptions.
How we work within it
Where delivery includes commercial electronic messaging on your behalf, the work is run to your consent records and CASL obligations, with identification and unsubscribe handling built into the process rather than left to the agent.
What you can request
You can request the consent-handling approach, the sender identification and unsubscribe process, and the record-keeping method used for messaging performed on your behalf.

AODA

Accessibility for Ontarians with Disabilities Act

Ontario's accessibility law, relevant to customer service and digital deliverables in Ontario.

What it requires
Accessibility standards across customer service, information and communications and other areas, so that services and digital content are usable by people with disabilities, with documented policies and training.
How we work within it
Customer-facing delivery follows accessible service practices, and digital deliverables produced for you follow WCAG 2.1 AA aligned practices, so the work supports rather than undermines your own AODA obligations.
What you can request
You can request the accessible service approach, the accessibility standard applied to digital deliverables, and the training given to customer-facing staff.

Accessible Canada Act

Accessible Canada Act

Federal accessibility law aimed at a barrier-free Canada, relevant to federally regulated contexts.

What it requires
Identification and removal of barriers to accessibility in areas including employment, the built environment, information and communication technologies and the delivery of services, with a proactive, planned approach.
How we work within it
Accessibility is treated as a design requirement rather than an afterthought. Digital deliverables follow WCAG aligned practices and service processes are designed to be usable, supporting your obligations where the federal framework applies.
What you can request
You can request the accessibility approach for the relevant deliverables and services, and the standard applied to information and communications technology produced for you.

GDPR

General Data Protection Regulation

The European Union data protection regulation, relevant where EU personal data is in scope.

What it requires
A lawful basis for processing, data subject rights including access, rectification and erasure, data minimisation, purpose limitation, controller and processor obligations, safeguards for international transfers, and breach notification within defined timelines.
How we work within it
Where an engagement involves the personal data of EU data subjects, processing is aligned to GDPR principles, with the controller and processor roles, lawful basis and transfer safeguards set out in the contract and its data processing terms.
What you can request
You can request the processor commitments, the lawful basis and data subject rights handling, the international transfer safeguards and the breach notification timelines for EU personal data.

Frequently asked questions

Which privacy laws does Corpshore operate under by default?

PIPEDA, Canada's federal private-sector privacy law, applies by default to Canadian delivery, and Quebec Law 25, the most demanding privacy law in the country, applies to Quebec engagements. Provincial laws in Alberta and British Columbia, and Ontario PHIPA for health data, apply according to scope, which we confirm for your engagement rather than assume.

Does Corpshore comply with GDPR?

Where an engagement involves the personal data of European Union data subjects, processing is aligned to GDPR principles, with the controller and processor roles, lawful basis and international transfer safeguards set out in the contract and its data processing terms. GDPR is applied according to scope rather than claimed universally, and your counsel should confirm the arrangement.

How does Corpshore handle accessibility obligations?

Customer-facing delivery follows accessible service practices and digital deliverables follow WCAG 2.1 AA aligned practices, which support your obligations under AODA in Ontario and the Accessible Canada Act federally. Accessibility is treated as a design requirement rather than an afterthought, so the work supports rather than undermines your own accessibility position.

What compliance documentation can we request during due diligence?

You can request the data processing terms, a description of safeguards and access controls, the cross-border transfer position for your engagement, the breach notification process and the roles accountable for compliance. Regime-specific items, such as the Law 25 posture or the GDPR processor commitments, are available for the frameworks your engagement engages.

Does CASL affect outsourced marketing and outreach?

Yes, where delivery includes commercial electronic messaging on your behalf. The work is run to your consent records and CASL obligations, with sender identification and a functioning unsubscribe mechanism built into the process. You can request the consent-handling approach and the record-keeping method used for messaging performed on your behalf.

Do you hold specific security certifications?

This page describes our posture in terms of governance and process rather than listing certifications we cannot substantiate here. Where an engagement requires a specific attestation or audit, that is addressed directly in the contract and its schedules. We would rather commit to what we can document than claim a badge we cannot stand behind.

Is this page legal advice we can rely on?

No. It is general information about the compliance frameworks a Canadian engagement may touch, not legal advice. The specific commitments for your engagement are set out in the contract and its schedules and should be reviewed by your own counsel. What we commit to here is that the applicable position is documented and shared before go-live.

Build your Canadian team

Tell us the work, the languages and the coverage you need. You will have a considered response within six hours, or book a discovery call now.

Looking for a role rather than a partner? Explore careers at Corpshore Canada