✉️ MapleMail
Legal & compliance

Email privacy obligations for a Canadian business

Your mailbox is probably the largest uncatalogued store of customer personal information your business owns. Under PIPEDA, it is treated the same as any other one.

The short answer

A Canadian business mailbox holding customer names, addresses, phone numbers or financial details is a personal information store under PIPEDA. You owe it safeguards appropriate to how sensitive that information is, a record of every breach kept 24 months, breach reports where there is a real risk of significant harm, and answers to access requests within thirty days.

Ask a small business owner where they keep customer personal information and they will point at their bookkeeping software, or their booking system, or a spreadsheet. Almost nobody points at their inbox. Yet the inbox is usually the largest and least organised store of it in the whole business: quote requests with home addresses, appointment confirmations with phone numbers, a scanned void cheque a client sent because it was easier than typing the numbers, a message where someone explained a medical situation to justify a cancellation, a supplier thread with a staff member's SIN in an attachment nobody thought about again.

None of that was collected deliberately into a database. It arrived, one message at a time, and it stayed. And PIPEDA does not distinguish between information you meant to collect into a system and information that accumulated in a mailbox.

Why your mailbox is in scope at all

PIPEDA applies to every organization in respect of personal information that the organization collects, uses or discloses in the course of commercial activities [2]. There is no small-business exemption, no employee threshold, no revenue floor. The Office of the Privacy Commissioner describes commercial activity as any transaction, act or conduct, or regular course of conduct, of a commercial character [5]. If you invoice people, you are doing commercial activity.

Personal information itself is defined broadly: any factual or subjective information, recorded or not, about an identifiable individual - age, name, ID numbers, income, ethnic origin, blood type, opinions, evaluations, comments, employee files, credit records, medical records, even the existence of a dispute between a consumer and a merchant [5]. Read that list against your sent folder and the scope becomes obvious.

There is one useful carve-out. Business contact information - an employee's name, title, business address, telephone number or email address, collected, used or disclosed solely for the purpose of communicating with that person in relation to their employment or profession - is not covered [5]. So a mailbox full of supplier reps and trade contacts is a much smaller problem than one full of private customers. Most small businesses have both.

Jurisdiction adds a wrinkle. Alberta, British Columbia and Quebec have their own private-sector privacy laws deemed substantially similar to PIPEDA, and organizations subject to one of those are generally exempt from PIPEDA for information handled within that province [5]. But all businesses operating in Canada that handle personal information crossing provincial or national borders in the course of commercial activities are subject to PIPEDA regardless of where they are based [5]. A New Brunswick contractor emailing a Nova Scotia customer is not in a purely local situation.

Safeguards scale with sensitivity - that is the whole rule

Principle 7 is one sentence: personal information shall be protected by security safeguards appropriate to the sensitivity of the information [1]. Everything else is elaboration. The safeguards must protect against loss or theft as well as unauthorized access, disclosure, copying, use or modification, and organizations must protect personal information regardless of the format in which it is held [1]. Email is a format.

The nature of the safeguards varies with the sensitivity of the information collected, its amount, distribution and format, and the method of storage - and more sensitive information should be safeguarded by a higher level of protection [1]. This is the part people miss. There is no single standard for "a business mailbox". A mailbox holding nothing but appointment times and first names needs less than a mailbox where clients routinely describe health problems or send banking details.

Schedule 1 also tells you what counts as a safeguard, and the list is refreshingly plain: physical measures such as locked filing cabinets and restricted access to offices; organizational measures such as security clearances and limiting access on a need-to-know basis; and technological measures such as the use of passwords and encryption [1]. Two more clauses that get ignored: organizations must make employees aware of the importance of maintaining confidentiality of personal information [1], and care must be used in the disposal or destruction of personal information so unauthorized parties do not gain access to it [1]. That last one applies to the old laptop as much as to the mailbox on it.

Sensitivity is not a fixed property of a data type either. Schedule 1 notes that while some information - medical records, income records - is almost always sensitive, any information can be sensitive depending on context [1]. Names and addresses of magazine subscribers are generally not sensitive; names and addresses of subscribers to some special-interest magazines might be [1]. The same logic applies to your client list. A list of people who bought lumber is unremarkable. A list of people who booked a particular kind of counselling is not.

Responsibility follows the data, not the server

Most small businesses do not run their own mail server, which invites a comfortable assumption: security is the host's job. Schedule 1 closes that door. An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing, and the organization shall use contractual means to provide a comparable level of protection while the information is being processed by that third party [1].

Practically, your host is responsible for the infrastructure. You remain responsible to your customer. That does not mean hosting choice is irrelevant - a provider with weak account recovery or no multi-factor authentication makes your own obligation harder to meet - but it does mean you cannot delegate the obligation itself along with the mailbox.

The same principle requires an accountable individual: an organization must designate an individual or individuals accountable for compliance, and the identity of that person shall be made known on request [1]. In a two-person shop that is one of the two of you. It should still be a decided question rather than an unasked one.

Breach reporting: a high bar, and a record for everything

These are two different duties and they are constantly confused.

Reporting. An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual [2]. The same threshold triggers notification to the affected individual [2]. Significant harm is defined in the Act and it is broad: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on credit record, and damage or loss of property [2]. The factors relevant to whether the risk is real are the sensitivity of the personal information involved and the probability that it has been, is being, or will be misused [2]. Reports and notifications must be given as soon as feasible after the organization determines the breach occurred [2].

The regulations set out exactly what a report must contain: the circumstances and, if known, the cause; the day or period of the breach; a description of the personal information involved to the extent known; the number of individuals affected or an approximate number; the steps taken to reduce or mitigate harm; the steps taken or intended to notify individuals; and a contact person who can answer the Commissioner's questions [3]. Notice to individuals has a parallel list, including steps the individual themselves could take to reduce the risk [3]. Direct notification can be in person, by telephone, mail, email or any other form a reasonable person would consider appropriate [3]. The OPC accepts breach reports directly from organizations subject to PIPEDA [4].

Record-keeping. This one has no threshold. An organization shall keep and maintain a record of every breach of security safeguards involving personal information under its control [2], and the regulations require that record be kept for 24 months after the day the organization determines the breach occurred [3]. The record must contain information enabling the Commissioner to verify compliance with the reporting and notification duties [3], and the organization must provide the Commissioner access to it on request [2].

So the misdirected email that went to the wrong client and was recalled within a minute is almost certainly not reportable. It is still a breach you are supposed to write down. A privacy breach, as the OPC puts it, is the loss of, unauthorized access to, or disclosure of personal information, and breaches happen when personal information is stolen, lost, or mistakenly shared [4]. Mistakenly shared covers a great deal of ordinary email.

Knowingly contravening the reporting section or the record-keeping subsection is an offence, punishable on summary conviction by a fine up to $10,000 or, as an indictable offence, up to $100,000 [2]. Prosecutions of corner shops are not a live risk. The number is still there, and it is the tell that Parliament treated the record as a real duty rather than a suggestion.

Access requests land in your inbox, and so does the answer

Principle 9 gives an individual the right, on request, to be informed of the existence, use and disclosure of their personal information and to be given access to it, plus the right to challenge its accuracy and completeness and have it amended [1]. The organization must also provide an account of the use made of the information and an account of the third parties to whom it has been disclosed [1].

The mechanics are in the Act. The request must be made in writing [2]. You must assist an individual who says they need help preparing one [2]. You must respond with due diligence and in any case not later than thirty days after receipt, with an extension of up to another thirty days available if meeting the deadline would unreasonably interfere with your activities or necessary consultations make it impracticable - and you must send notice of the extension within the original thirty days, with reasons and a note of the individual's right to complain to the Commissioner [2]. Fail to respond in time and you are deemed to have refused [2]. Responses must be at minimal or no cost and in a form that is generally understandable [1].

Here is why this matters for email specifically. When a customer asks what you hold about them, the CRM record is the easy part - you export it. The hard part is the four years of correspondence in your mailbox, in threads with subject lines that do not include their name, in attachments, in messages forwarded to a staff member who has since left. If you have never searched your own mail archive for a customer's name, the first time you do it will not be on a thirty-day clock.

The honest concession

Most small business mailboxes will never be breached. The realistic threat to a two-person contracting firm is not a targeted attacker; it is a reused password, a phished login, or a laptop left in a truck. And the proportionate response at that scale is not an information security programme, a written policy binder, or a consultant's gap assessment.

It is three things. Strong unique passwords on every mailbox. Multi-factor authentication turned on. And no forwarding of customer email to personal accounts. That is it. Those three cover the overwhelming majority of realistic incidents, and they are defensible against a safeguards principle that asks for measures appropriate to sensitivity [1] rather than measures appropriate to a large organisation. If someone is selling you a compliance programme for a shop with two mailboxes and no health or financial data, you are being sold something you do not need.

The picture changes when the content changes. If clients routinely send you medical information, financial statements, or identity documents, you are in the higher-protection tier that Schedule 1 explicitly contemplates [1] - separate mailboxes with access on a need-to-know basis, a real answer to where attachments get saved, and a deletion habit, because information no longer required to fulfil identified purposes should be destroyed, erased or made anonymous [1].

Do this this week

Two jobs, an hour total. First, open your mail archive and search for the words most likely to mark sensitive content - "SIN", "void cheque", "diagnosis", "credit card", "passport", "date of birth". Whatever comes back tells you which tier of protection your mailbox actually needs, which is a question you currently cannot answer. Second, check whether any mailbox in the business forwards to a personal address, and turn it off. Then turn on multi-factor authentication everywhere it is available. If you want the paperwork side too, start a plain text file called breach-log.txt with columns for date, what happened, what information, how many people, what you did - because the duty to record every breach for 24 months [3] is the one duty here you cannot satisfy retroactively.

Foire aux questions

Does PIPEDA apply to my small business email?

If your business collects, uses or discloses personal information in the course of commercial activities, PIPEDA applies to that information - and email is one of the places it is held. The Act applies to every organization in respect of personal information collected, used or disclosed in the course of commercial activities. There is no employee-count or revenue threshold below which it stops applying.

Is a customer email address personal information?

A personal email address that identifies an individual generally is. Business contact information - an employee name, title, business address, telephone number or email address collected, used or disclosed solely to communicate with that person in relation to their employment or profession - is carved out. So emailing a purchasing manager at their work address is different from holding a private customer list.

How much security does the law actually require on a mailbox?

PIPEDA requires safeguards appropriate to the sensitivity of the information, protecting it against loss, theft, unauthorized access, disclosure, copying, use or modification, regardless of the format it is held in. The nature of the safeguards varies with sensitivity, amount, distribution, format and method of storage, and more sensitive information should be protected at a higher level. It does not prescribe specific products.

If my email is hosted by someone else, is the breach their problem?

Not entirely. Under Schedule 1, an organization is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and shall use contractual means to provide a comparable level of protection while the information is being processed by that third party. The provider handles the servers; the responsibility to the customer stays with you.

When do I have to report an email breach to the Privacy Commissioner?

When it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual. Significant harm includes humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on a credit record, and bodily harm. The relevant factors are the sensitivity of the information and the probability that it has been, is being, or will be misused.

Do I have to keep records of breaches that were not serious?

Yes. PIPEDA requires an organization to keep and maintain a record of every breach of security safeguards involving personal information under its control, and the regulations set that record period at 24 months after the day the organization determines the breach occurred. The reporting threshold is high; the record-keeping threshold is every breach.

What happens if a customer asks for every email I hold about them?

That is an access request under Principle 9. The request must be in writing, and the organization must respond with due diligence and in any case not later than thirty days after receiving it, with a possible extension of up to another thirty days in defined circumstances. Failing to respond in time is deemed a refusal. You must also account for how the information has been used and to whom it has been disclosed.

Is forwarding work email to my personal Gmail a problem?

It is the single most common way small businesses lose control of customer personal information. The copy in the personal account is outside whatever protections the business account has, outside any access-request search you run, and outside your ability to revoke it when a staff member leaves. It is also hard to square with a duty to safeguard information regardless of the format it is held in.

Sources

  1. PIPEDA Schedule 1 - the ten principles — S.C. 2000, c. 5, Sch. 1 - clauses 4.1.3, 4.3.4, 4.7-4.7.5, 4.9-4.9.4
  2. Personal Information Protection and Electronic Documents Act (full text) — ss. 4(1), 8(1)-(5), 10.1(1)-(8), 10.3(1)-(2), 28
  3. Breach of Security Safeguards Regulations, SOR/2018-64 — ss. 2, 3, 4, 6 - report contents, notification contents, 24-month record-keeping
  4. Office of the Privacy Commissioner - Report a privacy breach at your organization — Who reports to the OPC, and the definition of a privacy breach
  5. Office of the Privacy Commissioner - PIPEDA requirements in brief — Commercial activity, substantially similar provincial laws, what counts as personal information

Toutes les sources ont été vérifiées le 2026-08-28.

MapleMail is Canadian-hosted business email on your own domain, with per-mailbox accounts you actually control - so customer mail is not sitting in someone’s personal account.

See plans and pricing