SOC 2 and PIPEDA: how they fit
One is a voluntary audit a customer asked for. The other is federal law that applied to you the day you started handling personal information. They overlap in the controls, and nowhere else.
A SOC 2 report does not make you PIPEDA compliant, and PIPEDA compliance does not earn you anything in a SOC 2 report. They are different instruments with different audiences. SOC 2 is an attestation by a CPA firm, produced because a customer asked for evidence. PIPEDA is the Personal Information Protection and Electronic Documents Act, it is federal law, and it applies to a Canadian organisation handling personal information in commercial activity whether anyone asks or not.
Where they do meet is the control work. Roughly half of what you build for a SOC 2 Security scope is also what a privacy regulator would expect to see, and running both from one set of controls is cheaper than running them separately. What does not transfer is the obligations that have no SOC 2 equivalent, and those are the ones that cost Canadian companies money when they are discovered late.
What each one actually covers
| SOC 2 | PIPEDA | |
|---|---|---|
| What it is | An attestation report on controls | Federal statute |
| Who requires it | Your customer | Parliament |
| Who checks | A CPA firm you hire | The Office of the Privacy Commissioner of Canada, usually after a complaint or a breach |
| Applies when | You choose to commission it | You handle personal information in commercial activity |
| Scope | The system you describe | All personal information you hold, everywhere in the organisation, including employee records in federally regulated sectors |
| Output | A report with an opinion | No certificate, no report, nothing to hand a customer |
| Cost | $35,000 to $90,000 CAD in year one | $8,000 to $25,000 CAD of policy, process and records work if you start from nothing |
| Consequence of failing | A qualified opinion and awkward questions in a vendor review | Investigation, findings, and under Quebec's Law 25 penalties reaching four percent of worldwide turnover |
Where the control work overlaps
Build these once and both benefit.
| Control | Its SOC 2 home | Its privacy purpose |
|---|---|---|
| Access control and least privilege | CC6 | Limiting use of personal information to those who need it |
| Encryption in transit and at rest | CC6 | Safeguards proportionate to sensitivity |
| Vendor and subprocessor management | CC9 | Accountability for information transferred to third parties |
| Incident response and breach handling | CC7 | Breach of security safeguards reporting to the Commissioner and to affected individuals |
| Logging and monitoring | CC7 | Detecting and evidencing what happened to whose data |
| Employee training | CC1 | Demonstrating accountability under the first principle |
| Data inventory | Scoping and the system description | Knowing what you hold, why, and for how long. The foundation of everything else |
The data inventory is the one worth doing first regardless of which instrument drove you here. You cannot draw a SOC 2 system boundary without it, and you cannot answer a PIPEDA access request without it either. It also turns up verbatim in the system description, which is the longest section of the report a buyer reads.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What PIPEDA requires that SOC 2 never asks about
None of these appear in a SOC 2 Security scope, and a clean report says nothing about them.
- Meaningful consent. Whether the individual understood what they agreed to, in language they could follow, at the point of collection.
- Purpose limitation. Collecting only what the identified purpose requires, and not repurposing it later without fresh consent.
- Right of access. An individual can ask what you hold about them, and you have thirty days to respond. The process for handling that request has to exist before the request arrives.
- Right to correction. And an obligation to pass corrections to third parties who received the original.
- Retention limits. Personal information is kept only as long as the purpose requires, then destroyed. Indefinite retention is a contravention on its own.
- Breach of security safeguards records. You must keep a record of every breach, whether or not it was reportable, and produce those records to the Commissioner on request.
- A designated accountable individual. Someone is responsible for compliance and their contact information is available on request.
- Openness. Your practices have to be published in a form an ordinary person can understand.
The PIPEDA compliance guide works through each of the ten principles and what evidence a Canadian company should keep for them.
The SOC 2 Privacy criteria are not PIPEDA
SOC 2 has an optional Privacy category, and it is the source of most of the confusion here. Those criteria come from the Generally Accepted Privacy Principles developed by the AICPA with CPA Canada. They test whether you handle personal information the way your own notices say you do. That is not the same as testing whether those commitments satisfy Canadian law.
You can hold a clean SOC 2 report covering Privacy and still be in contravention of PIPEDA, if what you promised was not enough. Most Canadian companies are better off taking Security only in the report and running the statutory work separately, unless a customer named Privacy in a contract. The Trust Services Criteria page sets out the reasoning.
Quebec, Alberta, British Columbia and health information
PIPEDA is the federal default and provincial statutes displace it in some places, which matters if you have customers or employees outside Ontario.
| Where | Statute | What is different |
|---|---|---|
| Most of Canada | PIPEDA | The federal baseline. Ten principles, thirty-day access response, mandatory breach reporting |
| Quebec | Law 25 | Stricter. Named privacy officer, privacy impact assessments, an assessment before transferring information outside Quebec, and much larger penalties |
| Alberta and British Columbia | Provincial PIPA | Substantially similar to PIPEDA for provincially regulated organisations, with their own regulators |
| Ontario health information | PHIPA | Applies instead, for that information. If you hold health records for a clinic or hospital you are likely an agent under the Act. See SOC 2 and PHIPA |
Law 25 is the one that catches SaaS companies out, because the transfer assessment applies to ordinary vendor decisions. Connecting your HR system to an American compliance platform is a transfer of personal information outside Quebec and requires the assessment first. Nothing in your SOC 2 process will prompt you to do it. The Law 25 page works through which duties a SOC 2 report evidences and which ten it does not touch at all, and the data residency page covers where the transfer question meets your hosting decision.
The order that saves money
Do the data inventory once, use it to draw both the SOC 2 system boundary and the privacy record of processing, and keep one control set that both the auditor and a regulator would recognise. Companies that run these as two projects a year apart pay for the inventory twice.
What to tell a buyer who asks about both
Enterprise security schedules increasingly ask for a SOC 2 report and for confirmation of Canadian privacy compliance in the same questionnaire. Answer them as two things, because they are. Attach the report for the first. For the second, point at your privacy policy, your named accountable individual, your breach procedure, your retention schedule and your subprocessor list. If your report period ended some months ago, send a bridge letter with it, and price the whole exercise from the Canadian cost breakdown rather than from a US vendor's blog. A buyer who gets a report in response to a privacy question asks a follow-up question, which is a week you did not need to spend.
Get quotes that cover the scope you actually need
Tell us what the customer asked for and we will put it in front of Canadian firms that do both sides of this work.
Get matchedCommon questions
Does SOC 2 make us PIPEDA compliant?
No. SOC 2 is a voluntary attestation about controls in a system you describe. PIPEDA is federal law covering all personal information you hold, including obligations SOC 2 never examines such as consent, purpose limitation, access requests and retention limits. A clean report is useful evidence of safeguards and it is not a compliance finding.
Should we include the Privacy criteria in our SOC 2?
Only if a customer named it in writing. The Privacy category tests whether you keep your own privacy commitments, adds 20 to 30 percent to the audit fee, and does not address your statutory duties. Most Canadian companies take Security only and run privacy compliance as separate work.
Do we need PIPEDA compliance if all our customers are American?
Yes, if you are a Canadian organisation collecting personal information in commercial activity, including from your own employees in federally regulated sectors and from your customers' end users. PIPEDA follows the organisation, not the customer, and it applies to cross-border transfers of that information as well.
How much does PIPEDA compliance cost compared with SOC 2?
Far less. Building a privacy program from nothing is typically $8,000 to $25,000 CAD of policy, inventory and process work, with no audit fee because nobody audits PIPEDA. A first SOC 2 is $35,000 to $90,000 CAD. The overlap in control work means doing both together costs less than the two figures added up.
Does Quebec's Law 25 change our SOC 2 scope?
Not the scope of the report, but it changes what you have to do alongside it. Law 25 requires a named privacy officer, privacy impact assessments for certain projects, and a documented assessment before personal information is transferred outside Quebec. Connecting an American compliance platform to your HR system is such a transfer.