Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Privacy Commissioner of Canada publishes guidance for businesses on third party service providers

The Privacy Commissioner of Canada (OPC) is accepting comments until December 4, 2026, on its new guidance for businesses engaging third party service providers. Commissioner Philippe Dufresne published this guidance on September 10, 2026, to assist organisations in assessing privacy approaches before commencing work. Organisations remain responsible for personal information under their control, even when processed by a third party.

The new guidance from the OPC helps businesses subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) evaluate potential third party service provider privacy practices. It outlines best practices to identify privacy and compliance risks, inform decisions about working with providers, shape contractual terms, and demonstrate accountability to regulatory bodies. Commissioner Dufresne stated that compliance with privacy law by organisations and their third party partners is essential to protect individuals privacy and personal information. He also noted that investing in privacy protection can be a competitive advantage for organisations seeking to earn Canadians trust.

The Privacy Commissioner of Canada consistently addresses the challenges of data stewardship in an interconnected digital economy, as evidenced by this September 2026 guidance.

Guidance on assessing third party service providers published by the Privacy Commissioner of Canada

Who this binds
Organisations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada are legally bound by the Act, and this guidance provides advisory best practices for their compliance.
What changed
The Privacy Commissioner of Canada published new guidance on September 10, 2026, clarifying best practices for organisations to assess third party service providers.
What to check
Organisations should review the new guidance to ensure their third party service provider assessment processes align with the recommended best practices.
What this does not mean
This guidance does not introduce new legal obligations beyond those already established under the Personal Information Protection and Electronic Documents Act (PIPEDA) for organisations in Canada.

Not settled: The guidance is currently open for comments until December 4, 2026, after which the document may be updated.

Send this to your team

The Privacy Commissioner of Canada published guidance on September 10, 2026, for Canadian organisations subject to PIPEDA, detailing best practices for assessing third party service providers and accepting comments until December 4, 2026.

Today's question

The Privacy Commissioner of Canada (OPC) published guidance for organisations engaging third party service providers. What is a key principle highlighted in this guidance regarding an organisation's responsibility for personal information?

  1. Organisations remain responsible for personal information under their control, even when processed by a third party.
  2. Third party service providers assume full responsibility for personal information once it is transferred to them for processing.
  3. The Privacy Commissioner of Canada will directly regulate third party service providers to ensure compliance with PIPEDA.
  4. Organisations are only responsible for personal information collected directly by them, not data collected by a third party on their behalf.

Answer this question on the site

Worth knowing

  1. Korea raises data breach fines to 10% of revenue

    Organisations operating in South Korea must reassess their data protection compliance and incident response plans given the substantial increase in potential financial penalties for data breaches.

  2. AdaptHealth data breach affects 4.1 million individuals

    The AdaptHealth breach affecting 4.1 million individuals signals that even large healthcare providers remain significant targets for cyberattacks, requiring privacy professionals in that sector to regularly reassess their breach prevention and response strategies.

  3. Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers

    This enforcement action by the Dutch DPA against Uber demonstrates how automated decision making, particularly when affecting individuals' employment or access to services, remains a significant area of regulatory scrutiny under GDPR Article 22.

  4. Healthcare organisations tackle AI governance in fragmented regulatory environment

    This IAPP report on healthcare organisations tackling AI governance in a fragmented regulatory environment demonstrates the sector specific challenges in implementing AI governance frameworks, directly impacting compliance strategies for health data.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.