Back to Compliance

PIPEDA Compliance

Personal Information Protection and Electronic Documents Act

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law for private-sector organizations. It sets out ground rules for how businesses must handle personal information in the course of their commercial activities. VitaScribe is committed to full compliance with PIPEDA's requirements.

The 10 Fair Information Principles

PIPEDA is built around ten fair information principles that form the foundation of our privacy practices:

1. Accountability

VitaScribe is responsible for personal information under its control and has designated a Privacy Officer who is accountable for our compliance.

Privacy Officer oversight and direct contact

2. Identifying Purposes

We clearly identify the purposes for which personal information is collected at or before the time of collection.

Detailed privacy notices for all data

3. Consent

We obtain informed consent from individuals for the collection, use, or disclosure of their personal information.

Clear consent mechanisms and withdrawal options

4. Limiting Collection

We limit our collection of personal information to what is strictly necessary for the purposes identified.

Minimum information collection approach

5. Limiting Use & Retention

We do not use or disclose information for secondary purposes, and retain information only as long as necessary.

Established data retention and destruction policies

6. Accuracy

We keep personal information as accurate and up-to-date as necessary for the identified purposes.

User-driven information update capabilities

7. Safeguards

We protect personal information with security safeguards appropriate to the sensitivity of the information.

E2E encryption and regular assessments

8. Openness

We make information about our personal information policies and practices readily available to the public.

Clear, accessible privacy documentation

9. Individual Access

Upon request, we provide individuals access to their information and the ability to challenge its accuracy.

Timely response to access requests

10. Challenging Compliance

Individuals can address a challenge concerning our compliance with the above principles to our Privacy Officer.

Established clear complaints procedure

Implementation Measures

Privacy by Design

We incorporate privacy protections into our product development process from the outset, not as an afterthought.

Privacy Impact Assessments

We conduct regular assessments to identify and mitigate privacy risks before they occur.

Employee Training

All employees receive comprehensive privacy training to ensure they understand their responsibilities.

Data Breach Protocol

We maintain robust procedures for responding to and reporting privacy breaches in accordance with requirements.

Have questions about our PIPEDA compliance?