Last updated: March 1, 2026
Table of Contents
01
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law that governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities.
PIPEDA is built on 10 fair information principles:
02
BrokersAtlas meets all applicable regulatory requirements for Canadian privacy, anti-spam, and insurance industry standards. Below is an overview of our compliance status.
| Regulation | Status | Scope |
|---|---|---|
| PIPEDA | Compliant | Federal privacy law for commercial organizations |
| CASL | Compliant | Anti-spam legislation for commercial electronic messages |
| Quebec Law 25 | Compliant | Quebec privacy modernization law (all 3 phases) |
| Alberta PIPA | Compliant | Alberta private sector privacy legislation |
| BC PIPA | Compliant | British Columbia private sector privacy legislation |
| Provincial Insurance Regs | Compliant | Insurance licensing and conduct across all provinces |
| OSFI Guidelines | Compliant | Federal guidelines for technology and cyber risk |
| PCI DSS | Compliant | Payment card data security standards |
03
AtlasBrokers implements the following measures to comply with PIPEDA:
04
We collect the following categories of personal information with your consent:
05
Transparency in how we handle your data throughout its entire lifecycle, from collection to secure deletion.
| Data Category | Processing Purpose | Retention Period |
|---|---|---|
| Account Data | Service delivery and authentication | Account lifetime + 30 days |
| Broker Profiles | Directory listings and search | Active listing + 90 days |
| Reviews & Ratings | Community trust and transparency | Indefinite (anonymized on deletion) |
| Usage Analytics | Service improvement | 24 months (aggregated) |
| Payment Data | Transaction processing | 7 years (regulatory requirement) |
| Support Tickets | Customer service | 3 years after resolution |
| Server Logs | Security monitoring | 90 days |
06
We retain personal information only as long as necessary:
07
Under PIPEDA, you have the following rights regarding your personal information:
08
We provide comprehensive self-service privacy controls so you can manage your personal information directly from your account dashboard.
Export all your personal data in machine-readable formats (JSON, CSV). Available in your account settings. Requests fulfilled within 72 hours.
Request complete deletion of your account and all associated data. Irreversible after 30-day grace period. Regulatory retention may apply.
Granular consent controls for marketing emails, analytics tracking, third-party sharing, and cookie preferences. Update anytime.
09
Every access to personal data is logged with comprehensive audit trails, ensuring full accountability and transparency.
Audit Log Sample
Read access for support ticket #T-2847
By: admin@atlasbrokers.ca | Resource: Broker Profile #4821
User-initiated full data export (JSON)
By: user@example.com | Resource: Account Data Export
Opted out of email marketing
By: user2@example.com | Resource: Marketing Preferences
Automated purge: 1,247 records older than 24 months
By: system | Resource: Expired Analytics Records
All audit logs are immutable, encrypted, and retained for a minimum of 7 years. Logs include: timestamp, actor identity, IP address, action type, affected resource, and outcome.
10
We use the following third-party service providers to operate the Service:
11
We plan to engage independent auditors to assess our security controls, privacy practices, and regulatory compliance on a regular basis.
Firm: Independent CPA Firm
Frequency: Annual
Target: Q4 2026
Firm: External Privacy Consultants
Frequency: Annual + as needed
Target: Q3 2026
Firm: Accredited Security Firm
Frequency: Periodic
Target: Q2 2026
Firm: Compliance Advisors
Frequency: Semi-annual
Target: Q3 2026
12
In the event of a data breach, we follow the mandatory breach notification requirements under PIPEDA and Quebec Law 25 (Loi 25):
13
Select your province to generate a tailored compliance checklist for insurance brokers operating in your jurisdiction.
14
Recent regulatory changes affecting insurance brokers in Canada. We continuously monitor and adapt to evolving compliance requirements.
Final phase of Quebec's privacy law mandates data portability rights and enhanced consent mechanisms for all organizations handling Quebec residents' data.
Updated guidelines requiring federally regulated insurers to maintain comprehensive cyber risk frameworks with board-level reporting.
The Privacy Commissioner updated breach reporting thresholds and introduced new requirements for documenting breach response timelines.
New guidance from the Canadian Council of Insurance Regulators on requirements for online insurance brokerages and digital distribution channels.
CRTC issued updated guidance on implied vs. express consent for commercial electronic messages in the insurance sector.
15
For any privacy-related questions, concerns, or requests, please contact our Privacy Officer:
Privacy Officer privacy@atlasbrokers.ca
General Inquiries legal@atlasbrokers.ca
Company: AtlasBrokers Inc.
Location: Toronto, Ontario, Canada
You may also file a complaint directly with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or by calling 1-800-282-1376.