The short answer
A Canadian business mailbox holding customer names, addresses, phone numbers or financial details is a personal information store under PIPEDA. You owe it safeguards appropriate to how sensitive that information is, a record of every breach kept 24 months, breach reports where there is a real risk of significant harm, and answers to access requests within thirty days.
Ask a small business owner where they keep customer personal information and they will point at their bookkeeping software, or their booking system, or a spreadsheet. Almost nobody points at their inbox. Yet the inbox is usually the largest and least organised store of it in the whole business: quote requests with home addresses, appointment confirmations with phone numbers, a scanned void cheque a client sent because it was easier than typing the numbers, a message where someone explained a medical situation to justify a cancellation, a supplier thread with a staff member's SIN in an attachment nobody thought about again.
None of that was collected deliberately into a database. It arrived, one message at a time, and it stayed. And PIPEDA does not distinguish between information you meant to collect into a system and information that accumulated in a mailbox.
Why your mailbox is in scope at all
PIPEDA applies to every organization in respect of personal information that the organization collects, uses or discloses in the course of commercial activities [2]. There is no small-business exemption, no employee threshold, no revenue floor. The Office of the Privacy Commissioner describes commercial activity as any transaction, act or conduct, or regular course of conduct, of a commercial character [5]. If you invoice people, you are doing commercial activity.
Personal information itself is defined broadly: any factual or subjective information, recorded or not, about an identifiable individual - age, name, ID numbers, income, ethnic origin, blood type, opinions, evaluations, comments, employee files, credit records, medical records, even the existence of a dispute between a consumer and a merchant [5]. Read that list against your sent folder and the scope becomes obvious.
There is one useful carve-out. Business contact information - an employee's name, title, business address, telephone number or email address, collected, used or disclosed solely for the purpose of communicating with that person in relation to their employment or profession - is not covered [5]. So a mailbox full of supplier reps and trade contacts is a much smaller problem than one full of private customers. Most small businesses have both.
Jurisdiction adds a wrinkle. Alberta, British Columbia and Quebec have their own private-sector privacy laws deemed substantially similar to PIPEDA, and organizations subject to one of those are generally exempt from PIPEDA for information handled within that province [5]. But all businesses operating in Canada that handle personal information crossing provincial or national borders in the course of commercial activities are subject to PIPEDA regardless of where they are based [5]. A New Brunswick contractor emailing a Nova Scotia customer is not in a purely local situation.
Safeguards scale with sensitivity - that is the whole rule
Principle 7 is one sentence: personal information shall be protected by security safeguards appropriate to the sensitivity of the information [1]. Everything else is elaboration. The safeguards must protect against loss or theft as well as unauthorized access, disclosure, copying, use or modification, and organizations must protect personal information regardless of the format in which it is held [1]. Email is a format.
The nature of the safeguards varies with the sensitivity of the information collected, its amount, distribution and format, and the method of storage - and more sensitive information should be safeguarded by a higher level of protection [1]. This is the part people miss. There is no single standard for "a business mailbox". A mailbox holding nothing but appointment times and first names needs less than a mailbox where clients routinely describe health problems or send banking details.
Schedule 1 also tells you what counts as a safeguard, and the list is refreshingly plain: physical measures such as locked filing cabinets and restricted access to offices; organizational measures such as security clearances and limiting access on a need-to-know basis; and technological measures such as the use of passwords and encryption [1]. Two more clauses that get ignored: organizations must make employees aware of the importance of maintaining confidentiality of personal information [1], and care must be used in the disposal or destruction of personal information so unauthorized parties do not gain access to it [1]. That last one applies to the old laptop as much as to the mailbox on it.
Sensitivity is not a fixed property of a data type either. Schedule 1 notes that while some information - medical records, income records - is almost always sensitive, any information can be sensitive depending on context [1]. Names and addresses of magazine subscribers are generally not sensitive; names and addresses of subscribers to some special-interest magazines might be [1]. The same logic applies to your client list. A list of people who bought lumber is unremarkable. A list of people who booked a particular kind of counselling is not.
Responsibility follows the data, not the server
Most small businesses do not run their own mail server, which invites a comfortable assumption: security is the host's job. Schedule 1 closes that door. An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing, and the organization shall use contractual means to provide a comparable level of protection while the information is being processed by that third party [1].
Practically, your host is responsible for the infrastructure. You remain responsible to your customer. That does not mean hosting choice is irrelevant - a provider with weak account recovery or no multi-factor authentication makes your own obligation harder to meet - but it does mean you cannot delegate the obligation itself along with the mailbox.
The same principle requires an accountable individual: an organization must designate an individual or individuals accountable for compliance, and the identity of that person shall be made known on request [1]. In a two-person shop that is one of the two of you. It should still be a decided question rather than an unasked one.
Breach reporting: a high bar, and a record for everything
These are two different duties and they are constantly confused.
Reporting. An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual [2]. The same threshold triggers notification to the affected individual [2]. Significant harm is defined in the Act and it is broad: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on credit record, and damage or loss of property [2]. The factors relevant to whether the risk is real are the sensitivity of the personal information involved and the probability that it has been, is being, or will be misused [2]. Reports and notifications must be given as soon as feasible after the organization determines the breach occurred [2].
The regulations set out exactly what a report must contain: the circumstances and, if known, the cause; the day or period of the breach; a description of the personal information involved to the extent known; the number of individuals affected or an approximate number; the steps taken to reduce or mitigate harm; the steps taken or intended to notify individuals; and a contact person who can answer the Commissioner's questions [3]. Notice to individuals has a parallel list, including steps the individual themselves could take to reduce the risk [3]. Direct notification can be in person, by telephone, mail, email or any other form a reasonable person would consider appropriate [3]. The OPC accepts breach reports directly from organizations subject to PIPEDA [4].
Record-keeping. This one has no threshold. An organization shall keep and maintain a record of every breach of security safeguards involving personal information under its control [2], and the regulations require that record be kept for 24 months after the day the organization determines the breach occurred [3]. The record must contain information enabling the Commissioner to verify compliance with the reporting and notification duties [3], and the organization must provide the Commissioner access to it on request [2].
So the misdirected email that went to the wrong client and was recalled within a minute is almost certainly not reportable. It is still a breach you are supposed to write down. A privacy breach, as the OPC puts it, is the loss of, unauthorized access to, or disclosure of personal information, and breaches happen when personal information is stolen, lost, or mistakenly shared [4]. Mistakenly shared covers a great deal of ordinary email.
Knowingly contravening the reporting section or the record-keeping subsection is an offence, punishable on summary conviction by a fine up to $10,000 or, as an indictable offence, up to $100,000 [2]. Prosecutions of corner shops are not a live risk. The number is still there, and it is the tell that Parliament treated the record as a real duty rather than a suggestion.
Access requests land in your inbox, and so does the answer
Principle 9 gives an individual the right, on request, to be informed of the existence, use and disclosure of their personal information and to be given access to it, plus the right to challenge its accuracy and completeness and have it amended [1]. The organization must also provide an account of the use made of the information and an account of the third parties to whom it has been disclosed [1].
The mechanics are in the Act. The request must be made in writing [2]. You must assist an individual who says they need help preparing one [2]. You must respond with due diligence and in any case not later than thirty days after receipt, with an extension of up to another thirty days available if meeting the deadline would unreasonably interfere with your activities or necessary consultations make it impracticable - and you must send notice of the extension within the original thirty days, with reasons and a note of the individual's right to complain to the Commissioner [2]. Fail to respond in time and you are deemed to have refused [2]. Responses must be at minimal or no cost and in a form that is generally understandable [1].
Here is why this matters for email specifically. When a customer asks what you hold about them, the CRM record is the easy part - you export it. The hard part is the four years of correspondence in your mailbox, in threads with subject lines that do not include their name, in attachments, in messages forwarded to a staff member who has since left. If you have never searched your own mail archive for a customer's name, the first time you do it will not be on a thirty-day clock.
The honest concession
Most small business mailboxes will never be breached. The realistic threat to a two-person contracting firm is not a targeted attacker; it is a reused password, a phished login, or a laptop left in a truck. And the proportionate response at that scale is not an information security programme, a written policy binder, or a consultant's gap assessment.
It is three things. Strong unique passwords on every mailbox. Multi-factor authentication turned on. And no forwarding of customer email to personal accounts. That is it. Those three cover the overwhelming majority of realistic incidents, and they are defensible against a safeguards principle that asks for measures appropriate to sensitivity [1] rather than measures appropriate to a large organisation. If someone is selling you a compliance programme for a shop with two mailboxes and no health or financial data, you are being sold something you do not need.
The picture changes when the content changes. If clients routinely send you medical information, financial statements, or identity documents, you are in the higher-protection tier that Schedule 1 explicitly contemplates [1] - separate mailboxes with access on a need-to-know basis, a real answer to where attachments get saved, and a deletion habit, because information no longer required to fulfil identified purposes should be destroyed, erased or made anonymous [1].
Do this this week
Two jobs, an hour total. First, open your mail archive and search for the words most likely to mark sensitive content - "SIN", "void cheque", "diagnosis", "credit card", "passport", "date of birth". Whatever comes back tells you which tier of protection your mailbox actually needs, which is a question you currently cannot answer. Second, check whether any mailbox in the business forwards to a personal address, and turn it off. Then turn on multi-factor authentication everywhere it is available. If you want the paperwork side too, start a plain text file called breach-log.txt with columns for date, what happened, what information, how many people, what you did - because the duty to record every breach for 24 months [3] is the one duty here you cannot satisfy retroactively.