The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada’s federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in commercial activity. IT decisions affect PIPEDA: where data is stored, who can access backups, how long logs are kept, and how quickly you notify the Privacy Commissioner after a breach that poses real risk of significant harm. MSPs handling personal data are often considered service providers with contractual obligations. Practical steps include data inventories, least-privilege access, encryption in transit and at rest, and written agreements with vendors that describe security safeguards and breach reporting timelines.