Why a routine business decision can become a privacy project


Your business has found a cloud service that will make work easier. Staff are using spreadsheets and separate email accounts, and the new software would give them a shared record of customer enquiries, billing information and previous conversations. The price is reasonable. There is a discount available if you sign soon.
You send the agreement to your lawyer for a quick review. It seems like a small purchase.
Then the questions start. What information will go into the system? Who will have access? What can the supplier do with it? Has anyone reviewed the software’s AI features?
Those questions can make a straightforward purchase feel unnecessarily complicated. But the price of the software says very little about the privacy exposure your business is accepting. An inexpensive service could hold years of customer records, and a problem involving those records could cost considerably more than the subscription.
The review starts with understanding what your business intends to put into the system. Customer contact details are one thing. Years of correspondence, attachments and staff notes may contain considerably more personal information than anyone considered when choosing the software.
Does the business need to import all of those records? Which employees need access? Will the information be used only for customer service, or will other teams use it for marketing, analysis or another purpose?
These are decisions about how your business handles information. The supplier’s agreement may not answer them, but the answers affect whether the service and its protections are suitable.
Your business also needs to understand the supplier’s role. Can it use customer information for its own purposes? Can other providers access the records? What happens to the information when you stop using the service? These are among the issues identified in joint Canadian privacy-regulator guidance on cloud services.
AI features add further questions. Will the supplier use customer information or employee prompts to train or improve its models? Where are those prompts and outputs retained? Canadian privacy regulators expressly identify the reuse of personal information from prompts for model training as a secondary purpose that providers should explain.
For an Alberta business subject to the Personal Information Protection Act, or PIPA, using a supplier does not end the business’s responsibilities. Section 5(2) makes an organization responsible for its service provider’s compliance with the Act in respect of the services provided.
Where the information is handled also matters. If your business uses a service provider outside Canada, PIPA section 6(2) requires policies addressing the countries where information is or may be handled and the purposes for which the provider is authorized to collect, use or disclose it.
The applicable rules can change with the business and its activities. Commercial information flows across provincial or national borders can engage federal privacy law. Operations involving Quebec or the EU may also require a separate review under Quebec’s private-sector privacy law or the EU’s General Data Protection Regulation. The analysis depends on the business’s activities and connections to the jurisdiction, as well as the information involved.
Even after the agreement has been reviewed, someone needs to put the protections into practice. The supplier may offer access restrictions that your business must configure. Someone needs to decide which employees can see particular records and remove access when employees change roles or leave.
That work may involve the business owner, IT, legal counsel and whoever manages the records. In a smaller business, one person may perform several of those functions. What matters is that the decisions are made and someone is responsible for carrying them out.
When those arrangements are missing, a contract review can expose gaps in the business’s existing practices. That is how a request for a quick review becomes a larger privacy project.
The consequences become clearer if something goes wrong after the software is in use. Suppose the supplier reports that someone may have accessed customer information without authorization. Your business needs to establish which records were involved, what happened and who could be affected.
Under PIPA section 34.1, an organization must notify Alberta’s Commissioner without unreasonable delay where a reasonable person would consider that the loss, unauthorized access or unauthorized disclosure of personal information under its control creates a real risk of significant harm to an individual. Assessing that obligation may depend on information your business needs from the supplier.
There may also be investigation costs, legal fees, customer communications and claims. If the incident interrupts the service, employees may lose access to records they need to do their work.
Insurance then becomes relevant. Cyber insurance may address certain response expenses or privacy claims, but whether it responds to a particular incident, and how much exposure remains with your business, depends on the policy and the facts.
A significant incident can therefore demand attention from finance, communications, senior management and the board. The original purchase price does little to explain the scale of the resulting problem.
This helps explain why privacy work can be undervalued. At the point of purchase, its most visible effects may be additional questions and a delay in signing. The value of understanding and addressing the exposure can be harder to see until something goes wrong.
A useful starting point for legal advice is the proposed agreement and a short description of how your business plans to use the service. Counsel can help identify the missing information, assess the contractual protections and explain what needs to be resolved before you commit. The review should leave your business with decisions it can put into practice.
Calling it a “small deal” does not make the privacy exposure small. Discounted pricing is a poor reason to commit your business to risks it has not understood.
If your business is considering a software purchase, contact Roy Legal to discuss the agreement and your intended use.
This article provides general information only and is not legal advice. Reading or relying on it does not create a solicitor-client relationship with Andrew Roy or Roy Legal. Laws and their interpretation may change, and their application depends on the circumstances. Obtain legal advice about your specific situation before acting on this information.
© 2026 Andrew Roy. All rights reserved.




Comments