Insights › Compliance
Building software that handles Canadian client data responsibly
If your software stores personal information about Canadians, privacy obligations are a design input, not a legal formality to sort out later. The federal baseline is PIPEDA, with provincial equivalents in some jurisdictions and additional rules for health information. This is not legal advice, and you should get a lawyer's read on your specific obligations. But there are architectural decisions that are far cheaper to make early.
Consent has to be recorded, not assumed
It is not enough that a client agreed at some point. You need to know what they agreed to, when, and under which version of your terms. That means storing the consent event, the document version, and a timestamp, and being able to produce it later. A boolean column called consent will not survive a serious question.
People can ask what you hold, and they can ask you to change it
Access, correction, and withdrawal requests are real workflows. If answering one means a developer writing custom queries across eight tables, it will be slow and error-prone. Design for it: know where personal data lives, and build the ability to export or correct a person's record as a normal feature.
Retention means deletion actually happening
A retention policy that exists only in a document is not a control. If you say you keep records for seven years, something has to enforce it. Scheduled jobs that expire and purge data on the stated schedule turn a policy into a practice, and give you something concrete to point at.
Log access to sensitive records
When data is sensitive, knowing who looked at it matters as much as who changed it. Audit logging is straightforward to build in from the start and awkward to add once the application has grown. The same applies to row-level access rules in multi-tenant systems, where the cost of one data leak between tenants is severe.
Encrypt tokens and credentials properly
Integrations mean you will be holding access tokens for other systems. Storing them in plain text is a common shortcut and a genuinely bad one. Use your platform's secret storage or a vault, and make rotation possible without a migration.
Why this is worth doing early
Every item here is ordinary engineering work if planned in and a disruptive retrofit if not. Consent records cannot be backfilled truthfully. Audit logs cannot tell you about access that happened before they existed. Building these in from the start also turns out to be a competitive advantage when clients start asking harder questions.
Need a hand with this?
We help businesses design, build, and run systems that hold up. Free initial consultation.