PIPEDA and provincial privacy rules in Canada, HIPAA and state privacy law in the US: the obligations differ by where you operate, but the underlying mechanics repeat: data minimization, consent, access-request handling, and a notification clock that starts the moment personal information is exposed. We translate compliance into a plan.
Practical guidance on Canadian federal and provincial privacy obligations, scoped to what actually applies to your organization. That includes how you collect, use, and disclose personal information under PIPEDA's data minimization principle (collect only what a stated purpose actually requires), what meaningful consent needs to look like, and how your organization responds to an individual's access request within the required timeframe under PIPEDA and the relevant provincial regime.
For US operations, guidance on HIPAA's safeguard and minimum-necessary-use requirements where it applies, and on the state privacy laws relevant to where your organization and customers are located, including how each handles a consumer's data subject access request (DSAR). State privacy law varies significantly by jurisdiction, so guidance is scoped to where your customers actually are, not a generic national summary that misses state-specific obligations.
A clear picture of what you're required to do, and by when, if personal information is ever exposed, so that decision isn't made under pressure for the first time. That includes who has to be notified (regulators, affected individuals, and in some jurisdictions credit bureaus), the specific notification clock each applicable law starts, and what documentation regulators expect to see afterward, mapped out in advance rather than researched during an actual incident.
Most engagements start with a short intake: where your organization operates, where your customers and employees are located, and what kind of personal information you collect and process, including whether you're minimizing collection to what's actually needed or holding more than the law expects you to justify. That determines which obligations actually apply: a Canadian credit union's PIPEDA and provincial obligations look different from a US professional services firm juggling several states' privacy statutes and their DSAR response windows, and a healthcare-adjacent client layers HIPAA on top of whichever of those also applies. From there, we translate the relevant obligations into a plain-language summary of what your team actually has to do differently, and where policy needs to be created or updated.
A frequent misconception is that privacy consulting and cybersecurity are the same conversation. They're related but distinct. Cybersecurity is about preventing and containing an incident; privacy consulting is about what the law requires of you once personal information is involved, before and after that incident. Getting a breach-notification clock wrong, or missing that a particular provincial or state regulator needed to be told, is a real legal exposure even when the security incident itself was handled well.
These are standards we help clients meet, not certifications Cyberwall holds. See our Compliance Services page for the frameworks we hold or help clients meet more broadly. Privacy obligations are also enforced differently than security frameworks: there's typically no single certificate to earn, just an ongoing duty to handle personal information correctly and to notify the right people, in the right timeframe, if that duty is ever breached.
Book a preparedness call to see exactly where your gaps are.