Compliance How-To

How to Conduct a Privacy Audit for Your Canadian Business: DIY Checklist

A privacy audit checklist for Canadian businesses: what to review, what evidence to collect, and how to turn findings into a fix list.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
14 min read
Privacy Audit Canada
PIPEDA Audit
Privacy Checklist
Compliance Review
DIY Compliance

A privacy audit is the most valuable thing you can do for your business's compliance posture. A systematic audit reveals your real risk exposure, identifies quick wins, and creates the documentation you'll need if the OPC ever comes calling.

This guide walks you through a practical DIY privacy audit that any business can complete without hiring a law firm.

Last updated: April 2026

Why Conduct a Privacy Audit?

A privacy audit serves multiple purposes:

  • Risk identification: Find vulnerabilities before they become breaches
  • Regulatory readiness: Demonstrate compliance efforts to the OPC
  • Trust building: Know that your business actually handles data responsibly
  • Reform readiness: Be positioned to respond as federal privacy reform (Bill C-36, not yet law) progresses
  • Insurance: Many cyber insurers require documented privacy programmes

You can do it yourself using this guide and tools like Canada Compliance AI.

Phase 1: Data Inventory (2–4 hours)

1.1 Map Your Data Flows

Create a simple spreadsheet that captures, for each type of personal information you collect:

ColumnWhat to Record
Data typeCustomer names, email addresses, payment info, etc.
SourceHow you collect it (web form, purchase, phone, etc.)
Storage locationCRM, accounting software, email platform, file server, paper
Retention periodHow long you keep it
Who has accessStaff roles with access
Third partiesVendors or services with access
Legal basisConsent, contract, legal obligation

Starting points for your inventory:

  • Your website forms (contact, sign-up, checkout)
  • Your CRM or customer database
  • Your accounting/bookkeeping software
  • Your email marketing platform
  • Your payroll system
  • Paper records and filing cabinets
  • Email inboxes

1.2 Identify Sensitive Information

Flag any information that is considered sensitive under PIPEDA:

  • Health and medical information
  • Social Insurance Numbers (SINs)
  • Financial account details
  • Biometric data
  • Racial or ethnic origin
  • Religious beliefs
  • Sexual orientation

Sensitive information requires higher safeguards and typically explicit consent.

1.3 Identify Orphan Data

Look for personal information being collected that serves no clear purpose — especially in legacy systems, old email archives, or spreadsheets created for one-time projects. This is data you should probably delete.

Audit questions:

  • Do you collect data you never actually use?
  • Are there backup files or archived data that contain personal information and have been forgotten?
  • Does every software system you use have a clear data inventory?

Phase 2: Consent and Transparency Review (2–3 hours)

2.1 Privacy Policy Audit

Review your existing privacy policy (or create one if you don't have one):

  • Does your privacy policy exist and is it publicly accessible on your website?
  • Does it accurately describe all data you actually collect?
  • Does it name the types of third parties you share data with?
  • Does it disclose if data is stored or processed outside Canada?
  • Does it explain how to file a privacy complaint?
  • Does it identify your Privacy Officer's contact information?
  • Is it written in plain language (no legal jargon)?
  • Does it include a "last updated" date within the past 12 months?

2.2 Consent Mechanism Audit

For each point where you collect personal information:

  • Website contact forms: Is the purpose stated? Is marketing consent separate?
  • Checkout process: Is the email opt-in separate and unchecked by default?
  • Newsletter sign-ups: Is the consent language specific to what you'll send?
  • Service agreements: Do client contracts address data collection and use?
  • Employee onboarding: Are employees informed about monitoring and data practices?

Document your consent records: can you prove, for each marketing subscriber, when and how they consented?

2.3 CASL Audit

  • Do all commercial emails include your business name, address, and unsubscribe link?
  • Do you process unsubscribes within 10 business days?
  • Do you have documented consent for every marketing subscriber?
  • Are any subscribers relying on implied EBR consent that is about to expire?
  • Are there any subscribers you can't document consent for?

Phase 3: Security Assessment (2–3 hours)

3.1 Technical Security

  • Are all devices containing personal information encrypted (full-disk encryption)?
  • Are strong passwords (12+ characters) and two-factor authentication required for all systems?
  • Are software systems kept up to date with security patches?
  • Is there a regular data backup with encrypted off-site or cloud storage?
  • Are backups tested periodically (can you actually restore from them)?
  • Is your Wi-Fi network protected with WPA3 encryption?
  • Are USB drives allowed on office computers? (They shouldn't be without controls.)

3.2 Access Controls

  • Do staff members only have access to the personal information they need for their job?
  • Are passwords changed when employees leave?
  • Are shared logins or shared passwords used? (They shouldn't be.)
  • Is there a log of who has accessed sensitive systems?

3.3 Physical Security

  • Are paper files containing personal information stored in locked cabinets?
  • Is there a clean desk policy for sensitive documents?
  • Are documents containing personal information shredded (not just recycled) when disposed of?
  • Is access to areas with sensitive records controlled?

Phase 4: Vendor and Third-Party Review (1–2 hours)

For every software platform, service provider, or consultant that handles your customers' personal information:

  • Do you have a written contract with them that addresses data protection?
  • Does the contract require them to protect data to PIPEDA standards?
  • Does it restrict their use of your data to providing their services to you?
  • Do you know where they store the data (Canada vs international)?
  • Is there a provision for what happens to the data if you end the relationship?

Create a vendor register listing each vendor, what data they access, where it's stored, and whether a data processing agreement is in place.

High-priority vendors to review:

  • CRM (Salesforce, HubSpot, Zoho)
  • Email marketing (Mailchimp, Klaviyo, Constant Contact)
  • Cloud storage (Google Drive, Dropbox, Microsoft OneDrive)
  • Accounting software (QuickBooks, Xero)
  • Payroll provider
  • IT support / managed service provider
  • Website hosting

Phase 5: Incident Response Readiness (1 hour)

  • Do you have a written breach response procedure?
  • Does it define who is responsible for breach response?
  • Does it include steps for containing, assessing, and reporting a breach?
  • Do you have the OPC's breach report contact information? (priv.gc.ca)
  • Is there a template for notifying affected individuals?
  • Do you maintain a breach register (required under PIPEDA for 2 years)?
  • Are staff trained on how to identify and report a suspected breach?

Phase 6: Training and Culture (30 minutes)

  • Have all employees received privacy awareness training in the past 12 months?
  • Do new employees receive privacy training during onboarding?
  • Do employees know who the Privacy Officer is and how to reach them?
  • Are employees aware of CASL requirements for business email?
  • Is there a process for employees to raise privacy concerns confidentially?

Documenting Your Audit Findings

After completing each phase, document:

  1. Findings — what you discovered (good and bad)
  2. Gaps — where you are not meeting PIPEDA requirements
  3. Risk rating — high, medium, or low priority for each gap
  4. Remediation plan — what you'll do to close each gap, by when

This documentation is valuable evidence of a good-faith compliance programme if the OPC ever investigates.

After the Audit: Prioritising Remediation

Not every gap needs to be fixed immediately. Prioritise by risk:

Fix immediately (within 30 days):

  • No breach response procedure
  • No privacy policy on website
  • Unencrypted devices containing sensitive personal information
  • Marketing emails without unsubscribe links

Fix within 90 days:

  • Outdated consent records for marketing subscribers
  • Vendor contracts missing data protection clauses
  • Staff who haven't received privacy training

Fix within 6 months:

  • Outdated privacy policy
  • Consent language that doesn't meet best practices
  • Legacy data retained beyond necessary periods

Frequently Asked Questions

Q: How often should I conduct a privacy audit? A: Annually at minimum. Additionally, trigger an audit whenever you: launch a new product or service, change your technology stack significantly, merge with or acquire another business, or experience a privacy incident.

Q: Do I need to hire a lawyer to conduct a privacy audit? A: Not for a basic audit. This guide provides a solid framework for most SMBs. Engage a privacy lawyer for complex situations — major system changes, suspected OPC investigation risk, or significant data sharing arrangements.

Q: What should I do with the audit report? A: Keep it confidential (it identifies your vulnerabilities), act on the remediation plan, and review it annually. If the OPC investigates, the audit demonstrates your compliance efforts.

Q: Is there a standard format for a privacy audit? A: No mandatory format, but documenting your methodology, findings, and remediation plan in a clear written format is best practice.


Automate Your Ongoing Compliance

A one-time audit is valuable, but ongoing compliance monitoring is better. Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — and turn your one-time audit into a continuous programme.

Related reading: PIPEDA Compliance Checklist 2026 | PIPEDA Compliance Guide | OPC Self-Assessment Tool

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.