top of page
Search

Canada’s new third-party assessment guidance

Writer: Katarzyna  Celińska
Katarzyna Celińska
2 days ago
2 min read

Some time ago, I became more interested in Privacy in Canada. I even bought a book to prepare for the CIPP / C exam. I have practically finished it, but I still have not found the right moment to properly prepare for and take the exam. Too many things are happening in Cybersecurity, AI and GRC, so Canada had to wait on the shelf for a while.

But the Canadian privacy landscape is definitely worth following, especially because of its history, evolution and the way it works in practice.

 


Photo: magnific


The OPC of Canada has now published new guidance on assessing third party service providers. The document is aimed at organizations subject to PIPEDA that use third parties to collect, use, disclose or process personal information.


 

An organization remains responsible for personal information under its control, even when that information is processed by a third party. PIPEDA Principle 4.1.3 also requires organizations to use contractual or other means to ensure a comparable level of protection when personal information is processed by service providers.

 

The guidance recommends performing the assessment before onboarding the provider and covers areas that, from a TPRM perspective, are very familiar:

➡️ identifying what personal and sensitive information is involved,

➡️ mapping data flows and subcontractors,

➡️ understanding all processing purposes,

➡️ checking whether data is used for the provider’s own purposes, including algorithm training,

➡️ clarifying roles and responsibilities,

➡️ assessing cross-border processing,

➡️ reviewing security practices and breach-response responsibilities,

➡️ validating retention and deletion,

➡️ assessing vendor lock-in and lock-out,

➡️ monitoring the provider through logs, testing, inspections and independent audits.

 

I like the explicit recommendation to identify the source of training data when a provider uses AI. The guidance also asks organizations to scrutinize claims around anonymisation and consider whether supposedly anonymous information can actually be re-identified.

 

On paper, this looks mature. I see exactly the same challenge that we have under GDPR. Vendor privacy due diligence has become relatively standard in many organizations. Unfortunately, it is also very often reduced to a hasztag#compliance exercise:

send questionnaire → receive questionnaire → collect DPA → check the box → onboard vendor.

 

That is not a real risk assessment.

 

The OPC guidance also makes another important point: people performing these assessments should have appropriate expertise, and external legal or technical support may be needed where internal competencies are insufficient.


 
 
 

Comments


Stay in touch

META FOR MENA Information Technology Consultants Est.

City Avenue, 7th floor, office 706-0114

2 27 Street, Port Saeed, Deira, Dubai, United Arab Emirates
P.O. BOX: 40138
Licence N.O.: 1049080

​

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page