GetSOC2

SOC 2 and PIPEDA: how they fit

One is a voluntary audit a customer asked for. The other is federal law that applied to you the day you started handling personal information. They overlap in the controls, and nowhere else.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

A SOC 2 report does not make you PIPEDA compliant, and PIPEDA compliance does not earn you anything in a SOC 2 report. They are different instruments with different audiences. SOC 2 is an attestation by a CPA firm, produced because a customer asked for evidence. PIPEDA is the Personal Information Protection and Electronic Documents Act, it is federal law, and it applies to a Canadian organisation handling personal information in commercial activity whether anyone asks or not.

Where they do meet is the control work. Roughly half of what you build for a SOC 2 Security scope is also what a privacy regulator would expect to see, and running both from one set of controls is cheaper than running them separately. What does not transfer is the obligations that have no SOC 2 equivalent, and those are the ones that cost Canadian companies money when they are discovered late.

What each one actually covers

SOC 2 and PIPEDA side by side
SOC 2PIPEDA
What it isAn attestation report on controlsFederal statute
Who requires itYour customerParliament
Who checksA CPA firm you hireThe Office of the Privacy Commissioner of Canada, usually after a complaint or a breach
Applies whenYou choose to commission itYou handle personal information in commercial activity
ScopeThe system you describeAll personal information you hold, everywhere in the organisation, including employee records in federally regulated sectors
OutputA report with an opinionNo certificate, no report, nothing to hand a customer
Cost$35,000 to $90,000 CAD in year one$8,000 to $25,000 CAD of policy, process and records work if you start from nothing
Consequence of failingA qualified opinion and awkward questions in a vendor reviewInvestigation, findings, and under Quebec's Law 25 penalties reaching four percent of worldwide turnover

Where the control work overlaps

Build these once and both benefit.

Controls that serve a SOC 2 examination and a Canadian privacy program
ControlIts SOC 2 homeIts privacy purpose
Access control and least privilegeCC6Limiting use of personal information to those who need it
Encryption in transit and at restCC6Safeguards proportionate to sensitivity
Vendor and subprocessor managementCC9Accountability for information transferred to third parties
Incident response and breach handlingCC7Breach of security safeguards reporting to the Commissioner and to affected individuals
Logging and monitoringCC7Detecting and evidencing what happened to whose data
Employee trainingCC1Demonstrating accountability under the first principle
Data inventoryScoping and the system descriptionKnowing what you hold, why, and for how long. The foundation of everything else

The data inventory is the one worth doing first regardless of which instrument drove you here. You cannot draw a SOC 2 system boundary without it, and you cannot answer a PIPEDA access request without it either. It also turns up verbatim in the system description, which is the longest section of the report a buyer reads.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What PIPEDA requires that SOC 2 never asks about

None of these appear in a SOC 2 Security scope, and a clean report says nothing about them.

  • Meaningful consent. Whether the individual understood what they agreed to, in language they could follow, at the point of collection.
  • Purpose limitation. Collecting only what the identified purpose requires, and not repurposing it later without fresh consent.
  • Right of access. An individual can ask what you hold about them, and you have thirty days to respond. The process for handling that request has to exist before the request arrives.
  • Right to correction. And an obligation to pass corrections to third parties who received the original.
  • Retention limits. Personal information is kept only as long as the purpose requires, then destroyed. Indefinite retention is a contravention on its own.
  • Breach of security safeguards records. You must keep a record of every breach, whether or not it was reportable, and produce those records to the Commissioner on request.
  • A designated accountable individual. Someone is responsible for compliance and their contact information is available on request.
  • Openness. Your practices have to be published in a form an ordinary person can understand.

The PIPEDA compliance guide works through each of the ten principles and what evidence a Canadian company should keep for them.

The SOC 2 Privacy criteria are not PIPEDA

SOC 2 has an optional Privacy category, and it is the source of most of the confusion here. Those criteria come from the Generally Accepted Privacy Principles developed by the AICPA with CPA Canada. They test whether you handle personal information the way your own notices say you do. That is not the same as testing whether those commitments satisfy Canadian law.

You can hold a clean SOC 2 report covering Privacy and still be in contravention of PIPEDA, if what you promised was not enough. Most Canadian companies are better off taking Security only in the report and running the statutory work separately, unless a customer named Privacy in a contract. The Trust Services Criteria page sets out the reasoning.

Quebec, Alberta, British Columbia and health information

PIPEDA is the federal default and provincial statutes displace it in some places, which matters if you have customers or employees outside Ontario.

Which Canadian privacy law applies to a private-sector company
WhereStatuteWhat is different
Most of CanadaPIPEDAThe federal baseline. Ten principles, thirty-day access response, mandatory breach reporting
QuebecLaw 25Stricter. Named privacy officer, privacy impact assessments, an assessment before transferring information outside Quebec, and much larger penalties
Alberta and British ColumbiaProvincial PIPASubstantially similar to PIPEDA for provincially regulated organisations, with their own regulators
Ontario health informationPHIPAApplies instead, for that information. If you hold health records for a clinic or hospital you are likely an agent under the Act. See SOC 2 and PHIPA

Law 25 is the one that catches SaaS companies out, because the transfer assessment applies to ordinary vendor decisions. Connecting your HR system to an American compliance platform is a transfer of personal information outside Quebec and requires the assessment first. Nothing in your SOC 2 process will prompt you to do it. The Law 25 page works through which duties a SOC 2 report evidences and which ten it does not touch at all, and the data residency page covers where the transfer question meets your hosting decision.

The order that saves money

Do the data inventory once, use it to draw both the SOC 2 system boundary and the privacy record of processing, and keep one control set that both the auditor and a regulator would recognise. Companies that run these as two projects a year apart pay for the inventory twice.

What to tell a buyer who asks about both

Enterprise security schedules increasingly ask for a SOC 2 report and for confirmation of Canadian privacy compliance in the same questionnaire. Answer them as two things, because they are. Attach the report for the first. For the second, point at your privacy policy, your named accountable individual, your breach procedure, your retention schedule and your subprocessor list. If your report period ended some months ago, send a bridge letter with it, and price the whole exercise from the Canadian cost breakdown rather than from a US vendor's blog. A buyer who gets a report in response to a privacy question asks a follow-up question, which is a week you did not need to spend.

Get quotes that cover the scope you actually need

Tell us what the customer asked for and we will put it in front of Canadian firms that do both sides of this work.

Get matched

Common questions

Does SOC 2 make us PIPEDA compliant?

No. SOC 2 is a voluntary attestation about controls in a system you describe. PIPEDA is federal law covering all personal information you hold, including obligations SOC 2 never examines such as consent, purpose limitation, access requests and retention limits. A clean report is useful evidence of safeguards and it is not a compliance finding.

Should we include the Privacy criteria in our SOC 2?

Only if a customer named it in writing. The Privacy category tests whether you keep your own privacy commitments, adds 20 to 30 percent to the audit fee, and does not address your statutory duties. Most Canadian companies take Security only and run privacy compliance as separate work.

Do we need PIPEDA compliance if all our customers are American?

Yes, if you are a Canadian organisation collecting personal information in commercial activity, including from your own employees in federally regulated sectors and from your customers' end users. PIPEDA follows the organisation, not the customer, and it applies to cross-border transfers of that information as well.

How much does PIPEDA compliance cost compared with SOC 2?

Far less. Building a privacy program from nothing is typically $8,000 to $25,000 CAD of policy, inventory and process work, with no audit fee because nobody audits PIPEDA. A first SOC 2 is $35,000 to $90,000 CAD. The overlap in control work means doing both together costs less than the two figures added up.

Does Quebec's Law 25 change our SOC 2 scope?

Not the scope of the report, but it changes what you have to do alongside it. Law 25 requires a named privacy officer, privacy impact assessments for certain projects, and a documented assessment before personal information is transferred outside Quebec. Connecting an American compliance platform to your HR system is such a transfer.