Privacy obligations, made actionable.

PIPEDA and provincial privacy rules in Canada, HIPAA and state privacy law in the US: the obligations differ by where you operate, but the underlying mechanics repeat: data minimization, consent, access-request handling, and a notification clock that starts the moment personal information is exposed. We translate compliance into a plan.

Data minimization · live -
Collected for a stated purpose Retained only as long as required
Data narrows at every stage: only what's needed is collected, processed, retained, then deleted on schedule.
What's included

The obligations that apply to you, not a generic privacy primer.

01

PIPEDA & provincial guidance

Practical guidance on Canadian federal and provincial privacy obligations, scoped to what actually applies to your organization. That includes how you collect, use, and disclose personal information under PIPEDA's data minimization principle (collect only what a stated purpose actually requires), what meaningful consent needs to look like, and how your organization responds to an individual's access request within the required timeframe under PIPEDA and the relevant provincial regime.

02

HIPAA & US state privacy law

For US operations, guidance on HIPAA's safeguard and minimum-necessary-use requirements where it applies, and on the state privacy laws relevant to where your organization and customers are located, including how each handles a consumer's data subject access request (DSAR). State privacy law varies significantly by jurisdiction, so guidance is scoped to where your customers actually are, not a generic national summary that misses state-specific obligations.

03

Breach notification obligations mapped

A clear picture of what you're required to do, and by when, if personal information is ever exposed, so that decision isn't made under pressure for the first time. That includes who has to be notified (regulators, affected individuals, and in some jurisdictions credit bureaus), the specific notification clock each applicable law starts, and what documentation regulators expect to see afterward, mapped out in advance rather than researched during an actual incident.

How it works

Privacy law in plain terms, before it's an emergency.

Most engagements start with a short intake: where your organization operates, where your customers and employees are located, and what kind of personal information you collect and process, including whether you're minimizing collection to what's actually needed or holding more than the law expects you to justify. That determines which obligations actually apply: a Canadian credit union's PIPEDA and provincial obligations look different from a US professional services firm juggling several states' privacy statutes and their DSAR response windows, and a healthcare-adjacent client layers HIPAA on top of whichever of those also applies. From there, we translate the relevant obligations into a plain-language summary of what your team actually has to do differently, and where policy needs to be created or updated.

A frequent misconception is that privacy consulting and cybersecurity are the same conversation. They're related but distinct. Cybersecurity is about preventing and containing an incident; privacy consulting is about what the law requires of you once personal information is involved, before and after that incident. Getting a breach-notification clock wrong, or missing that a particular provincial or state regulator needed to be told, is a real legal exposure even when the security incident itself was handled well.

Common questions we get before signing on
  • "Is this the same as your Incident Response service?" No, Incident Response handles an active breach; Privacy Consulting is the groundwork done beforehand (and the notification/legal-obligation guidance during one) so the response isn't improvised.
  • "Do we need a lawyer instead?" Often both: we translate the operational and notification obligations into a plan your team can execute; legal counsel should still review anything with real legal exposure, and we work alongside counsel rather than in place of it.
  • "We operate in both Canada and the US, does that double the work?" It changes the mapping, not necessarily the workload. The goal is one coherent plan that accounts for every jurisdiction you actually touch, not two separate ones.
Privacy frameworks we work within

Scoped to wherever you and your customers actually are.

PIPEDA Provincial privacy laws HIPAA US state privacy laws Breach notification rules

These are standards we help clients meet, not certifications Cyberwall holds. See our Compliance Services page for the frameworks we hold or help clients meet more broadly. Privacy obligations are also enforced differently than security frameworks: there's typically no single certificate to earn, just an ongoing duty to handle personal information correctly and to notify the right people, in the right timeframe, if that duty is ever breached.

From the blog

Recent Privacy Breaches: A Wake Up Call →

Works with

Pairs naturally with these.

Not sure which privacy rules actually apply to you?

Book a preparedness call to see exactly where your gaps are.