Skip to content

Article

PIPEDA-aware SharePoint: a practical setup for Canadian SMBs

How to configure SharePoint Online so a Canadian small business can responsibly handle personal information under PIPEDA, without enterprise tooling or enterprise pricing.

By Embrollar Inc

This is a placeholder post — replace the body with the real article before launch.

What PIPEDA actually asks of an SMB

The Personal Information Protection and Electronic Documents Act doesn’t tell you to buy any particular product. It asks you to be accountable for personal information, limit collection to what you need, get reasonable consent, retain only as long as necessary, and protect what you keep.

For a small business, that translates into a small set of practical SharePoint configurations.

The controls that earn their keep

  • Sharing settings that default to “people in your organisation” rather than “anyone with the link”
  • A clear separation between client-data sites and internal collaboration sites
  • Sensitivity labels on the libraries that actually contain personal information
  • Retention policies that match what your business needs to keep, not what feels safe
  • Conditional access on accounts that touch the personal-information sites

What you can skip

Most enterprise compliance features are designed for organisations with full-time privacy officers. Small businesses don’t need eDiscovery or Insider Risk Management to do PIPEDA right — they need the basic configuration above and a written retention policy somebody actually reads.