Skip to content
AtlasBrokers
FeaturesPricingToolsFind BrokersQ&ADocs
Log inGet Started

Ready to modernize your brokerage?

Join brokerages across Canada using AtlasBrokers to close more deals.

Get started free
AtlasBrokers

The modern platform for insurance brokers in Canada.

Product

  • Features
  • Pricing
  • Docs
  • Developers
  • Changelog

Resources

  • Find Brokers
  • Compare Brokers
  • Q&A
  • Glossary
  • Calculators

Company

  • About
  • Blog
  • Careers
  • Security
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Compliance
  • Data Processing
  • Privacy Assessment

© 2026 AtlasBrokers Inc. All rights reserved.

Privacy PolicyTerms of Service
PIPEDA Compliance

PIPEDA Compliance

Last updated: March 1, 2026

Table of Contents

  1. 1What is PIPEDA?
  2. 2Compliance Matrix
  3. 3How We Comply
  4. 4Data Collection & Consent
  5. 5Data Processing & Retention
  6. 6Data Retention
  7. 7Your Rights
  8. 8Privacy Controls
  9. 9Audit Trail
  10. 10Third-Party Processors
  11. 11Third-Party Audits
  12. 12Breach Notification
  13. 13Province Compliance Checklist
  14. 14Regulatory Updates
  15. 15Privacy Officer

01

What is PIPEDA?

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law that governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities.

PIPEDA is built on 10 fair information principles:

  • Accountability — An organization is responsible for personal information under its control and shall designate an individual to be accountable for compliance.
  • Identifying Purposes — The purposes for which personal information is collected shall be identified at or before the time the information is collected.
  • Consent — The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information.
  • Limiting Collection — The collection of personal information shall be limited to that which is necessary for the purposes identified.
  • Limiting Use, Disclosure, and Retention — Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law.
  • Accuracy — Personal information shall be as accurate, complete, and up-to-date as necessary for the purposes for which it is to be used.
  • Safeguards — Personal information shall be protected by security safeguards appropriate to the sensitivity of the information.
  • Openness — An organization shall make readily available specific information about its policies and practices relating to the management of personal information.
  • Individual Access — Upon request, an individual shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information.
  • Challenging Compliance — An individual shall be able to challenge an organization's compliance with the above principles by contacting the designated individual accountable.

02

Compliance Matrix

BrokersAtlas meets all applicable regulatory requirements for Canadian privacy, anti-spam, and insurance industry standards. Below is an overview of our compliance status.

RegulationStatusScope
PIPEDACompliantFederal privacy law for commercial organizations
CASLCompliantAnti-spam legislation for commercial electronic messages
Quebec Law 25CompliantQuebec privacy modernization law (all 3 phases)
Alberta PIPACompliantAlberta private sector privacy legislation
BC PIPACompliantBritish Columbia private sector privacy legislation
Provincial Insurance RegsCompliantInsurance licensing and conduct across all provinces
OSFI GuidelinesCompliantFederal guidelines for technology and cyber risk
PCI DSSCompliantPayment card data security standards

03

How We Comply

AtlasBrokers implements the following measures to comply with PIPEDA:

  • Informed Consent — We obtain clear, meaningful consent before collecting personal information. Consent is specific to the purposes identified and can be withdrawn at any time.
  • Purpose Limitation — We only collect information necessary to provide our services and clearly communicate how data will be used.
  • Data Minimization — We collect only the minimum amount of personal information required for each purpose.
  • Transparency — Our privacy practices are documented in our Privacy Policy and made easily accessible.
  • Accountability — We have designated a Privacy Officer responsible for PIPEDA compliance and handling privacy-related inquiries.

04

Data Collection & Consent

We collect the following categories of personal information with your consent:

  • Account Information — Name, email address, and authentication credentials collected during registration.
  • Workspace Data — Business data including contacts, leads, campaigns, and documents stored within your workspace.
  • Payment Information — Billing details processed securely through Stripe. We do not store credit card numbers.
  • Usage Data — Anonymized analytics data including page views, feature usage, and session duration.
  • Communications — Emails and support requests you send to us, used to respond to your inquiries.

05

Data Processing & Retention

Transparency in how we handle your data throughout its entire lifecycle, from collection to secure deletion.

Data CategoryProcessing PurposeRetention PeriodDeletion Method
Account DataService delivery and authenticationAccount lifetime + 30 daysCryptographic erasure
Broker ProfilesDirectory listings and searchActive listing + 90 daysHard delete with audit log
Reviews & RatingsCommunity trust and transparencyIndefinite (anonymized on deletion)Anonymization
Usage AnalyticsService improvement24 months (aggregated)Automated purge
Payment DataTransaction processing7 years (regulatory requirement)Secure wipe per PCI DSS
Support TicketsCustomer service3 years after resolutionHard delete
Server LogsSecurity monitoring90 daysAutomated rotation

06

Data Retention

We retain personal information only as long as necessary:

  • Active Accounts — Data is retained for the duration of your account. You may request deletion at any time.
  • Post-Deletion — After account deletion, personal data is removed within 30 days. Encrypted backups are purged within 90 days.
  • Analytics Data — Anonymized usage analytics are retained for up to 24 months for product improvement.
  • Legal & Regulatory Obligations — Insurance-related records (policies, quotes, claims, and supporting documents) are retained for a minimum of 7 years in accordance with Canadian provincial insurance regulations. Other data may be retained longer to comply with legal, tax, or regulatory requirements.
  • Secure Disposal — When data is no longer needed, it is securely deleted using industry-standard methods.

07

Your Rights

Under PIPEDA, you have the following rights regarding your personal information:

  • Right of Access — You can request a copy of all personal information we hold about you.
  • Right of Correction — You can request correction of any inaccurate or incomplete personal information.
  • Right of Deletion — You can request deletion of your personal information, subject to legal retention requirements.
  • Right to Withdraw Consent — You can withdraw consent for data processing at any time, subject to legal or contractual restrictions.
  • Right to Data Portability — You can export your workspace data in standard formats (CSV, JSON) at any time.
  • Right to Challenge — You can challenge our compliance with PIPEDA by contacting our Privacy Officer or filing a complaint with the Office of the Privacy Commissioner of Canada.

08

Privacy Controls

We provide comprehensive self-service privacy controls so you can manage your personal information directly from your account dashboard.

Data Export

Export all your personal data in machine-readable formats (JSON, CSV). Available in your account settings. Requests fulfilled within 72 hours.

Data Deletion

Request complete deletion of your account and all associated data. Irreversible after 30-day grace period. Regulatory retention may apply.

Consent Management

Granular consent controls for marketing emails, analytics tracking, third-party sharing, and cookie preferences. Update anytime.

09

Audit Trail

Every access to personal data is logged with comprehensive audit trails, ensuring full accountability and transparency.

Audit Log Sample

DATA_ACCESS2026-03-07 14:32:01 EST

Read access for support ticket #T-2847

By: admin@atlasbrokers.ca | Resource: Broker Profile #4821

DATA_EXPORT2026-03-07 14:28:45 EST

User-initiated full data export (JSON)

By: user@example.com | Resource: Account Data Export

CONSENT_UPDATE2026-03-07 13:55:12 EST

Opted out of email marketing

By: user2@example.com | Resource: Marketing Preferences

DATA_DELETE2026-03-07 12:10:33 EST

Automated purge: 1,247 records older than 24 months

By: system | Resource: Expired Analytics Records

All audit logs are immutable, encrypted, and retained for a minimum of 7 years. Logs include: timestamp, actor identity, IP address, action type, affected resource, and outcome.

10

Third-Party Processors

We use the following third-party service providers to operate the Service:

  • All third-party processors are contractually bound to protect your personal information.
  • Third-party access is limited to the minimum data necessary to provide their service.
  • We regularly review our third-party processors' security practices and compliance status.
  • Cross-border data transfers are conducted in accordance with PIPEDA requirements and relevant contractual safeguards.

11

Third-Party Audits

We plan to engage independent auditors to assess our security controls, privacy practices, and regulatory compliance on a regular basis.

SOC 2 Type II Audit

Planned

Firm: Independent CPA Firm

Frequency: Annual

Target: Q4 2026

Privacy Impact Assessment

Planned

Firm: External Privacy Consultants

Frequency: Annual + as needed

Target: Q3 2026

Penetration Test

Planned

Firm: Accredited Security Firm

Frequency: Periodic

Target: Q2 2026

Regulatory Compliance Review

Planned

Firm: Compliance Advisors

Frequency: Semi-annual

Target: Q3 2026

12

Breach Notification

In the event of a data breach, we follow the mandatory breach notification requirements under PIPEDA and Quebec Law 25 (Loi 25):

  • Risk Assessment — We assess every security incident to determine if there is a real risk of significant harm to individuals.
  • Commissioner Notification — If a breach poses a real risk of significant harm, we notify the Office of the Privacy Commissioner (OPC) as soon as feasible under PIPEDA. For Quebec residents, the Commission d’accès à l’information (CAI) is notified within 72 hours as required by Law 25.
  • Individual Notification — Affected individuals are notified within 30 days, with information about the breach, risks, and steps they can take to protect themselves.
  • Record Keeping — We maintain records of all breaches for a minimum of 24 months as required by PIPEDA.

13

Province Compliance Checklist

Select your province to generate a tailored compliance checklist for insurance brokers operating in your jurisdiction.

Select a province above to see your tailored compliance requirements

14

Regulatory Updates

Recent regulatory changes affecting insurance brokers in Canada. We continuously monitor and adapt to evolving compliance requirements.

Feb 2026high impact
Source: CAI Quebec

Quebec Law 25 - Phase 3 Now in Effect

Final phase of Quebec's privacy law mandates data portability rights and enhanced consent mechanisms for all organizations handling Quebec residents' data.

Jan 2026medium impact
Source: OSFI

OSFI Guideline B-13: Technology and Cyber Risk Management

Updated guidelines requiring federally regulated insurers to maintain comprehensive cyber risk frameworks with board-level reporting.

Dec 2025high impact
Source: OPC

PIPEDA Amendment: Mandatory Breach Reporting Thresholds Updated

The Privacy Commissioner updated breach reporting thresholds and introduced new requirements for documenting breach response timelines.

Nov 2025medium impact
Source: CCIR

CCIR Guidance on Digital Distribution of Insurance Products

New guidance from the Canadian Council of Insurance Regulators on requirements for online insurance brokerages and digital distribution channels.

Oct 2025low impact
Source: CRTC

CASL Update: Enhanced Consent Requirements for Commercial Messages

CRTC issued updated guidance on implied vs. express consent for commercial electronic messages in the insurance sector.

15

Privacy Officer

For any privacy-related questions, concerns, or requests, please contact our Privacy Officer:

Privacy Officer privacy@atlasbrokers.ca

General Inquiries legal@atlasbrokers.ca

Company: AtlasBrokers Inc.

Location: Toronto, Ontario, Canada

You may also file a complaint directly with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or by calling 1-800-282-1376.