How to Conduct a Privacy Audit for Your Canadian Business: DIY Checklist
A privacy audit checklist for Canadian businesses: what to review, what evidence to collect, and how to turn findings into a fix list.
A privacy audit is the most valuable thing you can do for your business's compliance posture. A systematic audit reveals your real risk exposure, identifies quick wins, and creates the documentation you'll need if the OPC ever comes calling.
This guide walks you through a practical DIY privacy audit that any business can complete without hiring a law firm.
Last updated: April 2026
Why Conduct a Privacy Audit?
A privacy audit serves multiple purposes:
- Risk identification: Find vulnerabilities before they become breaches
- Regulatory readiness: Demonstrate compliance efforts to the OPC
- Trust building: Know that your business actually handles data responsibly
- Reform readiness: Be positioned to respond as federal privacy reform (Bill C-36, not yet law) progresses
- Insurance: Many cyber insurers require documented privacy programmes
You can do it yourself using this guide and tools like Canada Compliance AI.
Phase 1: Data Inventory (2–4 hours)
1.1 Map Your Data Flows
Create a simple spreadsheet that captures, for each type of personal information you collect:
| Column | What to Record |
|---|---|
| Data type | Customer names, email addresses, payment info, etc. |
| Source | How you collect it (web form, purchase, phone, etc.) |
| Storage location | CRM, accounting software, email platform, file server, paper |
| Retention period | How long you keep it |
| Who has access | Staff roles with access |
| Third parties | Vendors or services with access |
| Legal basis | Consent, contract, legal obligation |
Starting points for your inventory:
- Your website forms (contact, sign-up, checkout)
- Your CRM or customer database
- Your accounting/bookkeeping software
- Your email marketing platform
- Your payroll system
- Paper records and filing cabinets
- Email inboxes
1.2 Identify Sensitive Information
Flag any information that is considered sensitive under PIPEDA:
- Health and medical information
- Social Insurance Numbers (SINs)
- Financial account details
- Biometric data
- Racial or ethnic origin
- Religious beliefs
- Sexual orientation
Sensitive information requires higher safeguards and typically explicit consent.
1.3 Identify Orphan Data
Look for personal information being collected that serves no clear purpose — especially in legacy systems, old email archives, or spreadsheets created for one-time projects. This is data you should probably delete.
Audit questions:
- Do you collect data you never actually use?
- Are there backup files or archived data that contain personal information and have been forgotten?
- Does every software system you use have a clear data inventory?
Phase 2: Consent and Transparency Review (2–3 hours)
2.1 Privacy Policy Audit
Review your existing privacy policy (or create one if you don't have one):
- Does your privacy policy exist and is it publicly accessible on your website?
- Does it accurately describe all data you actually collect?
- Does it name the types of third parties you share data with?
- Does it disclose if data is stored or processed outside Canada?
- Does it explain how to file a privacy complaint?
- Does it identify your Privacy Officer's contact information?
- Is it written in plain language (no legal jargon)?
- Does it include a "last updated" date within the past 12 months?
2.2 Consent Mechanism Audit
For each point where you collect personal information:
- Website contact forms: Is the purpose stated? Is marketing consent separate?
- Checkout process: Is the email opt-in separate and unchecked by default?
- Newsletter sign-ups: Is the consent language specific to what you'll send?
- Service agreements: Do client contracts address data collection and use?
- Employee onboarding: Are employees informed about monitoring and data practices?
Document your consent records: can you prove, for each marketing subscriber, when and how they consented?
2.3 CASL Audit
- Do all commercial emails include your business name, address, and unsubscribe link?
- Do you process unsubscribes within 10 business days?
- Do you have documented consent for every marketing subscriber?
- Are any subscribers relying on implied EBR consent that is about to expire?
- Are there any subscribers you can't document consent for?
Phase 3: Security Assessment (2–3 hours)
3.1 Technical Security
- Are all devices containing personal information encrypted (full-disk encryption)?
- Are strong passwords (12+ characters) and two-factor authentication required for all systems?
- Are software systems kept up to date with security patches?
- Is there a regular data backup with encrypted off-site or cloud storage?
- Are backups tested periodically (can you actually restore from them)?
- Is your Wi-Fi network protected with WPA3 encryption?
- Are USB drives allowed on office computers? (They shouldn't be without controls.)
3.2 Access Controls
- Do staff members only have access to the personal information they need for their job?
- Are passwords changed when employees leave?
- Are shared logins or shared passwords used? (They shouldn't be.)
- Is there a log of who has accessed sensitive systems?
3.3 Physical Security
- Are paper files containing personal information stored in locked cabinets?
- Is there a clean desk policy for sensitive documents?
- Are documents containing personal information shredded (not just recycled) when disposed of?
- Is access to areas with sensitive records controlled?
Phase 4: Vendor and Third-Party Review (1–2 hours)
For every software platform, service provider, or consultant that handles your customers' personal information:
- Do you have a written contract with them that addresses data protection?
- Does the contract require them to protect data to PIPEDA standards?
- Does it restrict their use of your data to providing their services to you?
- Do you know where they store the data (Canada vs international)?
- Is there a provision for what happens to the data if you end the relationship?
Create a vendor register listing each vendor, what data they access, where it's stored, and whether a data processing agreement is in place.
High-priority vendors to review:
- CRM (Salesforce, HubSpot, Zoho)
- Email marketing (Mailchimp, Klaviyo, Constant Contact)
- Cloud storage (Google Drive, Dropbox, Microsoft OneDrive)
- Accounting software (QuickBooks, Xero)
- Payroll provider
- IT support / managed service provider
- Website hosting
Phase 5: Incident Response Readiness (1 hour)
- Do you have a written breach response procedure?
- Does it define who is responsible for breach response?
- Does it include steps for containing, assessing, and reporting a breach?
- Do you have the OPC's breach report contact information? (priv.gc.ca)
- Is there a template for notifying affected individuals?
- Do you maintain a breach register (required under PIPEDA for 2 years)?
- Are staff trained on how to identify and report a suspected breach?
Phase 6: Training and Culture (30 minutes)
- Have all employees received privacy awareness training in the past 12 months?
- Do new employees receive privacy training during onboarding?
- Do employees know who the Privacy Officer is and how to reach them?
- Are employees aware of CASL requirements for business email?
- Is there a process for employees to raise privacy concerns confidentially?
Documenting Your Audit Findings
After completing each phase, document:
- Findings — what you discovered (good and bad)
- Gaps — where you are not meeting PIPEDA requirements
- Risk rating — high, medium, or low priority for each gap
- Remediation plan — what you'll do to close each gap, by when
This documentation is valuable evidence of a good-faith compliance programme if the OPC ever investigates.
After the Audit: Prioritising Remediation
Not every gap needs to be fixed immediately. Prioritise by risk:
Fix immediately (within 30 days):
- No breach response procedure
- No privacy policy on website
- Unencrypted devices containing sensitive personal information
- Marketing emails without unsubscribe links
Fix within 90 days:
- Outdated consent records for marketing subscribers
- Vendor contracts missing data protection clauses
- Staff who haven't received privacy training
Fix within 6 months:
- Outdated privacy policy
- Consent language that doesn't meet best practices
- Legacy data retained beyond necessary periods
Frequently Asked Questions
Q: How often should I conduct a privacy audit? A: Annually at minimum. Additionally, trigger an audit whenever you: launch a new product or service, change your technology stack significantly, merge with or acquire another business, or experience a privacy incident.
Q: Do I need to hire a lawyer to conduct a privacy audit? A: Not for a basic audit. This guide provides a solid framework for most SMBs. Engage a privacy lawyer for complex situations — major system changes, suspected OPC investigation risk, or significant data sharing arrangements.
Q: What should I do with the audit report? A: Keep it confidential (it identifies your vulnerabilities), act on the remediation plan, and review it annually. If the OPC investigates, the audit demonstrates your compliance efforts.
Q: Is there a standard format for a privacy audit? A: No mandatory format, but documenting your methodology, findings, and remediation plan in a clear written format is best practice.
Automate Your Ongoing Compliance
A one-time audit is valuable, but ongoing compliance monitoring is better. Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — and turn your one-time audit into a continuous programme.
Related reading: PIPEDA Compliance Checklist 2026 | PIPEDA Compliance Guide | OPC Self-Assessment Tool
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Cloud Security Compliance Canada: AWS, Azure & GCP Privacy Configuration Guide 2026
Configure AWS, Microsoft Azure, and Google Cloud for Canadian privacy compliance. Data residency, en...
Small Business Data Protection Canada: Affordable Security Measures for SMBs in 2026
Practical data protection for Canadian small businesses: affordable security controls that satisfy P...