dog, corgi, pet, nature, cute, animal. Does PIPEDA apply to the client data a Canadian pet sitter keeps?
Photo by lucioliu on Pixabay

Guides

Does PIPEDA apply to the client data a Canadian pet sitter keeps?

A Canadian pet sitting business that holds client addresses, key codes or vet records is handling personal information under PIPEDA. Here is what that means.

What to take away

  • Charging for pet sitting is commercial activity, so PIPEDA covers the client names, addresses, key codes and vet records in your files. There is no revenue threshold and no small business exemption.
  • PIPEDA sets no fixed retention period. You choose how long each record is needed, write the period down, and destroy the record when that purpose ends.
  • Key and alarm codes need a written storage rule covering where they live, who can read them, how they travel to a backup sitter, and when they are deleted.
  • A client can ask to see the personal information you hold and ask you to correct it. Answer in writing, generally within 30 days, and log the request.
  • A one-person operation meets the law with a one-page policy, a locked cabinet or encrypted folder, and a destruction log.

Does PIPEDA apply to a small pet sitting business

The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of a commercial activity. Walking a dog for a fee is commercial activity, so the law reaches your client files.

The Office of the Privacy Commissioner of Canada sets out the scope of the law on its page about the Personal Information Protection and Electronic Documents Act.

There is no exemption based on revenue or headcount. A solo sitter in Halifax with a binder of client addresses is covered the same way as a franchise running twenty vans.

One wrinkle matters for sitters in provinces with their own private-sector privacy statutes. Quebec, British Columbia and Alberta have laws the federal government declared substantially similar. In those provinces, a provincially regulated business generally follows the provincial law for activity inside the province. PIPEDA still covers federally regulated work and cross-border handling.

Most pet sitting businesses are provincially regulated, and PIPEDA is the law they follow for client data. If you operate in Quebec, British Columbia or Alberta, check your provincial regulator as well.

The practical answer for a one-person operation: assume the law applies to you. The duties are modest, and building them into your pet sitting compliance checklist at the start costs far less than fixing a complaint later.

What PIPEDA asks of you

The core obligations are simple to state. Get consent before you collect personal information. Tell the client why you need it. Use it only for that purpose. Keep it accurate, and protect it with safeguards that match its sensitivity.

The Office of the Privacy Commissioner of Canada summarises these duties in its guide to PIPEDA requirements in brief. Ten fair information principles sit underneath them, covering accountability, identifying purposes, consent, limiting collection and safeguards.

You do not need a privacy officer with a law degree. You need a named person responsible for the file. In a one-person business that is you, and your policy should say so.

What counts as personal information in client records

Personal information is information about an identifiable individual. In a pet sitting file that covers more than most sitters expect.

Client records and sensitivity

Record

Client intake form
Name, address, phone
Key and alarm log
Codes, lockbox locations
Vet records
Pet health, payment details
Visit notes
Times, behaviour, home photos
Invoices and payments
Billing, card details

Personal info inside

Client intake form
Moderate
Key and alarm log
High
Vet records
Moderate to high
Visit notes
Moderate
Invoices and payments
High

Sensitivity

Client intake form
Key and alarm log
Vet records
Visit notes
Invoices and payments

Personal information in client records

RecordPersonal information inside itTypical sensitivity
Client intake formName, home address, phone, email, emergency contactModerate
Key and alarm logDoor key codes, alarm codes, lockbox locations, garage codesHigh
Vet recordsPet health history, vaccination dates, clinic name, sometimes the client's payment detailsModerate to high
Visit notesEntry and exit times, who was home, pet behaviour, photos of the homeModerate
Invoices and paymentsBilling address, card or bank details, service historyHigh

The address is the clearest case. It identifies a person and a place, and it tells anyone who reads it when the home is likely empty. That is why a leaked client list is a security problem and not just an embarrassment.

Vet records are a mixed file. The pet's health history is not personal information about a person, but the owner's name, contact details and payment arrangements usually sit in the same document. Treat the whole record as personal information and you will not go wrong.

Key codes are the record most sitters underrate. A four-digit alarm code attached to a street address is close to a burglary instruction. The Commissioner expects safeguards proportionate to sensitivity, which is why codes need more protection than a service schedule.

Health data and payment data

Some provinces treat health information under separate statutes. Veterinary records about a pet are not human health records, so those statutes generally do not apply. A client's own medical note, kept for an emergency contact, could fall under them.

Payment data is the other sensitive corner. If you store card numbers, your payment processor adds obligations on top of PIPEDA. The simplest fix is to let the processor hold the card and keep only the last four digits and the receipt in your own files.

Consent, collection and use of addresses and key codes

Consent can be express or implied, but it must be meaningful. A client who signs your service agreement and hands over a key has consented to you holding the address and the code for the purpose of walking the dog. That consent does not stretch to marketing, and it does not stretch to selling a client list.

Identify the purpose at the point of collection. Your intake form should say in one line what each field is for and who will see it. If a backup sitter may cover a visit, say so before the client signs, not after.

Limit collection to what you actually use. A birth date, a social insurance number or a copy of a driver's licence is almost never necessary for pet sitting. If you cannot name the purpose, do not collect the field.

The ten principles behind these rules are set out in the Commissioner's summary of PIPEDA fair information principles. Two of them do most of the work for a small sitter: identify the purpose, and collect only what you need for it.

Withdrawal and changes of mind

A client can withdraw consent at any time, subject to legal or contractual limits. If a client withdraws consent mid-booking, you may need to end the service rather than keep working without a key. Say that in your agreement so the conversation is not a surprise.

When a client moves or changes a code, update the record and destroy the old one. Stale codes in an old file are a small risk that costs nothing to remove.

Safeguarding vet records and entry codes

Safeguards must fit the sensitivity of the information and the size of your business. The Commissioner's guidance for businesses, collected under privacy for businesses, makes the point that safeguards scale. A solo sitter does not need a data centre, but does need more than an unlocked drawer.

For paper files, a locked filing cabinet in a room clients do not enter is enough. Do not leave intake forms on a car seat between visits. Do not photograph a client's key code on a phone that family members share.

For digital files, use a password manager for codes and a cloud drive with two-factor authentication for documents. Encrypt the device that holds client data. Keep the client list out of your personal email inbox where you can.

A key code storage policy should answer four questions in writing: where codes are kept, who can read them, how they are transmitted, and when they are deleted. A sitter who texts codes to a backup has answered the third question badly.

A worked example

A sitter in Winnipeg keeps intake forms in a locked cabinet, key codes in a password manager, and visit notes in a cloud folder with two-factor authentication. A backup sitter gets a code for one day through the password manager's sharing feature, which expires at midnight.

When a client cancels service, the sitter deletes the code from the manager, shreds the intake form, and logs both actions with the date. The vet record goes back to the client on request or is shredded when the retention period ends. The whole process takes about ten minutes per client.

That is a reasonable safeguard set for a one-person business. It is also easy to explain to a client who asks how their key is handled, which builds trust and reduces complaints.

Breach duties

PIPEDA requires you to report a breach of security safeguards to the Commissioner if it creates a real risk of significant harm, and to notify affected individuals. A lost phone with unencrypted client addresses and codes is the classic case.

Keep a breach log even when you decide a breach is not reportable. The record shows your reasoning if the Commissioner ever asks, and writing it down forces you to think the decision through.

A retention and destruction policy you can run

PIPEDA does not name a retention period. It requires you to destroy personal information once it is no longer needed for the purpose you collected it. You set the period, justify it, and follow it.

Retention and destruction schedule

Record

Key and alarm codes
Until last visit, then 30 days
Intake forms and visit notes
12 months after last service
Vet records
12 months after last service
Invoices and payment records
6 years from last tax year
Consent forms
6 years after last service

Retention period

Key and alarm codes
Delete from password manager
Intake forms and visit notes
Shred or delete
Vet records
Shred or delete
Invoices and payment records
Shred or delete
Consent forms
Shred or delete

Destruction method

Key and alarm codes
Intake forms and visit notes
Vet records
Invoices and payment records
Consent forms

The Canada Revenue Agency expects business records, including invoices, to be kept for six years from the end of the last tax year they relate to. That rule drives retention for billing records, not for key codes. Your pet sitting kpis can keep invoices for that period while the operational file is cleaned up much sooner.

A practical schedule for a Canadian pet sitting business looks like this:

Retention and destruction policy

RecordRetention periodDestruction method
Key and alarm codesUntil the last booked visit, then delete within 30 daysDelete from password manager, log the date
Intake forms and visit notes12 months after the last service, then reviewShred paper, delete digital copies
Vet records12 months after the last service, or return to clientShred or delete, note the choice
Invoices and payment records6 years from the end of the last tax yearShred or delete
Consent forms6 years after the last serviceShred or delete

Write the schedule into your policy and follow it. A retention rule you never apply is worse than no rule, because it looks like a safeguard you do not have.

Destruction that actually destroys

Shredding beats recycling for paper carrying addresses or codes. Deleting a file from a desktop is not enough if the drive is later sold, so wipe or encrypt drives before disposal. Empty the trash folder after digital deletions.

Keep a destruction log with the date, the record type and who destroyed it. One line per entry is enough. If a client asks whether you still hold their key code, the log answers in seconds.

Checklist for the retention policy

  • Every record type in your business has a named retention period.
  • Key codes are deleted within 30 days of the last booked visit.
  • Invoices are kept for six years to satisfy CRA requirements.
  • Destruction is logged with a date and a record type.
  • The policy names who is responsible for deletions.
  • The policy is reviewed once a year and dated.
  • Clients receive a copy of the policy at intake.

Handling access requests and complaints

A client can ask to see the personal information you hold about them and ask you to correct anything inaccurate. You must respond, and you should respond in writing.

Five steps for an access request

  1. Log date and requester name
  2. Confirm identity using contact on file
  3. Gather all records with their info
  4. Sever third-party information before release
  5. Respond in writing within 30 days

Set a target of 30 days. PIPEDA requires an answer within 30 days as a general rule, with limited extensions, so a 30-day internal target keeps you inside the law without tracking the fine print.

Verify identity before you disclose anything. A request by email from an address you have never seen is not proof that the person is the client. A short call to a number already on file closes that gap.

If you refuse a request, tell the client why and explain how to complain to the Office of the Privacy Commissioner of Canada. Do not ignore a request and hope it goes away.

The Commissioner's PIPEDA compliance help page includes tools aimed at small businesses, including a privacy checklist you can adapt.

The five steps for an access request

  1. Log the date the request arrived and the name of the requester.
  2. Confirm the requester's identity using a contact detail already on file.
  3. Gather every record that contains their personal information, including emails and visit notes.
  4. Review for any third-party information that should be severed before release.
  5. Reply in writing within 30 days, with the records or a written refusal and the complaint route.

Complaints and what follows

A client who is unhappy can complain to the Office of the Privacy Commissioner of Canada. The Commissioner can investigate, ask for records, and publish findings. Most complaints against small businesses end with a change to a practice rather than a penalty, but the time cost is real.

Good records are your defence. If you can show the consent form, the retention schedule and the destruction log, an investigation becomes a short conversation instead of a long one.

Practical compliance steps for a one-person operation

You can build a workable privacy setup in an afternoon. The point is not paperwork volume. It is knowing where client information lives, who can reach it, and when it goes away.

Start with a one-page privacy policy. It should cover what you collect, why, who sees it, how long you keep it, and how a client can ask to see or correct it. Hand it out with the service agreement and post it on your site.

Then map your records. Client information appears in several places:

Practical compliance steps

  • the intake binder
  • the phone
  • the cloud drive
  • the password manager
  • the email inbox
  • the accounting file Most sitters find one or two places they had forgotten.

Next, set the safeguards for each place and write the retention periods into a single schedule. Then train anyone who helps you, including a backup sitter or a family member who answers the phone.

Fit this work into your wider pet sitting operations rather than treating it as a separate project. Privacy tasks that live inside the daily routine get done; tasks that live in a folder do not.

Where privacy sits in the rest of your rules

Privacy is one compliance thread among several. Municipal business licensing, animal control bylaws such as Toronto Municipal Code Chapter 349, provincial consumer protection rules and commercial liability insurance all apply to a pet sitting business alongside PIPEDA. The pet sitting licensing requirements guide covers the licensing side.

Insurance matters here too. A care, custody and control policy responds when a pet is injured or a key is misused, but it does not cover a privacy breach. Do not assume one policy covers both risks.

A daily routine that keeps you compliant

Fold privacy into the tasks you already do. Add a code deletion to the file when a booking ends. Add a consent form to the intake pack. Add a line to your weekly admin block for reviewing new client records.

A written pet sitting sop checklist can carry these steps so they survive a busy week. The steps are small, and that is the point. Small steps taken every week beat a large cleanup once a year.

What to do first if you have done none of this

Delete the key codes you no longer need. That is the highest-risk record and the fastest win. Then write the one-page policy, then set the retention schedule, then build the destruction log.

If a client asks a question you cannot answer, say you will check and come back with an answer. Then check the Commissioner's guidance and reply. Honesty and a quick follow-up resolve most concerns before they become complaints.

Common questions

Does PIPEDA apply to a pet sitter with only a handful of clients?

Yes, if you charge for the service. PIPEDA applies to commercial activity, and there is no revenue threshold or small business exemption. A solo sitter with five clients is covered.

How long can I keep a client's key code?

Only as long as you need it. Delete it within 30 days of the last booked visit, or sooner if the client ends the service. Log the deletion date.

Do I need consent to share a client's address with a backup sitter?

Yes. Tell the client at intake who may see their information, including backup sitters, and get consent for that sharing before it happens.

What happens if a client asks to see their file?

You must respond, generally within 30 days, and provide the personal information you hold or a written refusal with the reason and the complaint route.

More in Guides

Latest from Standards Desk