PIPEDA and CASL Compliance for Business | North Star
HomeCompliancePIPEDA + CASL

Canadian privacy law,
implemented properly.

PIPEDA and CASL are not optional. Most BC small businesses are out of compliance without knowing it. We build the program from policy to evidence and operate it so you stay compliant year over year.

What's included

Everything you need, none of the upsell.

Real deliverables, with the boundaries written down. So you know what you're paying for and what counts as extra.

PIPEDA Program

Privacy by design.

Data inventory, retention schedules, consent flows, privacy officer support, and breach response. Documented and reviewed annually.

CASL Compliance

Marketing that's legal.

Consent capture and proof, suppression lists, opt-out plumbing, audit trail. So your campaigns don't hit a CRTC fine.

Breach Response

If it happens, you're ready.

Documented incident triage, OPC and CRTC reporting templates, customer notification scripts, and forensic plan.

Annual Review

Compliance doesn't expire.

Annual program review and external audit support. Updates when the law changes. So you're compliant in year three, not just at signup.

How it works

The order we work in.

A clear sequence so you can budget time, money, and risk against the work.

Step 01

Gap Assessment.

Map current state against PIPEDA principles and CASL requirements. Documented gap report.

Step 02

Remediate.

Build policies, deploy consent flows, set up suppression and tracking, train staff.

Step 03

Evidence.

Stand up the evidence library: training records, consent logs, breach drill records, policy reviews.

Step 04

Operate.

Quarterly internal review plus annual external audit support. Continuous policy updates.

FAQ

Common questions.

What is the difference between PIPEDA and CASL?

PIPEDA governs how you collect, use and disclose personal information. CASL governs commercial electronic messages, meaning consent to email or message people and what those messages must contain. Different obligations, commonly confused, and complying with one does not address the other.

Does PIPEDA apply to our business?

It applies to private-sector organisations collecting personal information in the course of commercial activity, across Canada, except in provinces with substantially similar legislation for intra-provincial activity, which is Alberta, BC and Quebec. Most businesses handling customer data are covered by one regime or the other.

What does CASL require for our email list?

Consent, which is either express or implied within defined limits and timeframes, identification of the sender, and a working unsubscribe honoured within ten business days. Records of consent matter, because the burden of proving consent is on the sender.

What happens if there is a breach?

Under PIPEDA, a breach of security safeguards creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner and to affected individuals, and a record must be kept of every breach whether reportable or not. Our decision tree walks the assessment.

Get a quote on pipeda + casl.

Tell us a bit about your environment and we'll come back with a scoped proposal in two business days. No obligation, no pressure.

Request a Quote Back to Compliance

Sources

Rules change. These are the bodies that publish them, so you can check the current text rather than take our summary for it.