New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Commerce & industry
Privacy & Security for E-commerce & DTC Brands
Your brand's data estate lives in software you rent: the storefront on Shopify or Lightspeed, flows in Klaviyo, pixels firing into Meta and Google, orders picked by a 3PL. Privacy Horizon builds the privacy and security program that stack needs, covering PCI's new SAQ A script expectations, Law 25's cookie and profiling duties, CASL consent and breach response, without asking you to hire a single executive.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Founder-led and Shopify Plus-tier brands headquartered in Toronto, Montreal or Vancouver, selling to consumers across Canada and the US, often shipping through an American 3PL with no in-house security or privacy staff. The person we usually meet first is the COO or CFO holding an acquirer letter or an insurance questionnaire.
Heads of e-commerce, CRM and marketing who own the Klaviyo account, the Meta and TikTok pixels, the GTM container and the consent platform, and need a straight answer on which campaigns CASL and Law 25 actually permit.
Omnichannel retailers running a few stores alongside e-com, subscription brands on Recharge-class billing, and any brand preparing for wholesale onboarding, a raise or aggregator due diligence.

Services
Privacy & security services for e-commerce & dtc brands
Each service below is scoped for how e-commerce & dtc brands actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for E-commerce & DTC Brands
vCISO for e-commerce and DTC brands: fractional security leadership for PCI SAQ scoping, cyber-insurance renewals and a stack that freezes for BFCM.
Virtual Privacy Officer
Virtual Privacy Officer for E-commerce & DTC Brands
Virtual Privacy Officer for e-commerce and DTC brands: Law 25 support, CASL consent records, pixel and e-receipt compliance from $2,200 CAD per month.
Penetration Testing
Penetration Testing for E-commerce & DTC Brands
Penetration testing for e-commerce and DTC brands: Shopify and headless storefronts, checkout scripts and loyalty APIs tested before the BFCM freeze.
Incident Response Planning
Incident Response Planning for E-commerce & DTC Brands
Incident response planning for e-commerce and DTC brands: first-hour playbooks for checkout skimmers, account takeover and vendor breaches, OPC to acquirer.
Privacy & Security Policy Development
Privacy & Security Policy Development for E-commerce & DTC Brands
Privacy policy development for e-commerce and DTC brands: pixel and SMS disclosures, Law 25 cookie notices and retention schedules for Canadian storefronts.
Privacy & Security Training
Privacy & Security Training for E-commerce & DTC Brands
Privacy and security training for e-commerce and DTC brands: CX scripts against order-data leaks, CASL literacy for marketing, refund-fraud drills before BFCM.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for E-commerce & DTC Brands
Vendor security review for e-commerce and DTC brands: vetting Shopify apps, SMS/email platforms and 3PLs, and knowing which need a SOC 2 report versus a DPA.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for E-commerce & DTC Brands
AI Privacy Impact Assessment for e-commerce and DTC brands: reviewing recommendation engines, AI chat and fraud-hold tools against PIPEDA and Law 25 duties.
What you hold
The customer data behind a DTC storefront
An online brand holds far more than orders. Each record type below sits in a different US-hosted SaaS tool, and every one of them is yours to protect under Canadian law.
Identity, orders and shipping history
Names, addresses, purchase and delivery records spread across the storefront, the 3PL's warehouse system and EDI feeds to wholesale partners.
Marketing consent and event data
SMS numbers with consent timestamps, email lists, behavioural events and the hashed emails matched to ad platforms through CAPI and Offline Conversions.
Loyalty balances and subscription records
Points ledgers in Smile.io-class tools plus subscription and dunning records in Recharge, all attractive targets for account-takeover fraud.
Support tickets and ID scans
Gorgias and Zendesk queues holding photos, addresses and sometimes identity documents collected for age-gated goods.
Card data you never touch
Tokens sit with the payment gateway, yet your acquirer still expects an annual PCI attestation and, under the updated SAQ A criteria, comfort about the scripts on your checkout page.
Employee and HR records
Payroll, SINs and banking details for head-office staff, exactly the files ransomware crews took in recent Canadian retail incidents.
Regulatory map
The rulebook for selling online in Canada
No single regulator covers an online store. Federal privacy law, Quebec's reform, anti-spam law and the card brands each reach a different part of the stack.
PIPEDA
Selling online is a commercial activity, so PIPEDA applies, and it follows personal information across provincial and national borders. A breach creating a real risk of significant harm must be reported to the OPC and affected customers as soon as feasible, with records kept for two years.
Quebec Law 25
Any brand with Quebec customers must designate a person in charge of personal information, publish that person's title, assess new systems and cross-border data flows, and keep a register of confidentiality incidents.
CASL
Email and SMS marketing requires express consent or a live existing business relationship, clear sender identification and an unsubscribe honoured within ten business days, with administrative monetary penalties reaching into the millions per violation.
PCI DSS v4.0.1 and the SAQ A change
SAQ A eligibility now includes confirming the site is protected against script attacks, and custom checkout JavaScript pushes a merchant into SAQ A-EP with Requirements 6.4.3 and 11.6.1 in scope.
Alberta and BC PIPA
Alberta requires notifying its Commissioner without unreasonable delay where a breach poses real risk of significant harm; BC's private-sector law has no mandatory reporting, though its OIPC strongly recommends it.
CCPA and US state privacy laws
California's law reaches brands doing business there above its revenue or data-volume thresholds, granting residents rights to know, delete, correct and opt out of sale or sharing.
What goes wrong
How Canadian online retailers actually get hurt
The incident record in Canadian retail is public and specific. These are the patterns a brand's program has to anticipate rather than discover.
Checkout skimming (Magecart)
A skimmer disguised as Google Tag Manager compromised the LCBO's online store, precisely the attack PCI's payment-page script requirements now target.
Loyalty account takeover
Credential-stuffing crews drained PC Optimum members' points using passwords reused from other services, and Loblaw's answer was to urge unique passwords.
Marketing-vendor breach
Giant Tiger's customer communications vendor was breached and millions of names, emails, phone numbers and addresses later leaked, with no payment data involved.
Ransomware against the retailer
Indigo lost its website and in-store POS for over a week while employee SINs and banking data were stolen; London Drugs closed every store as LockBit held head-office files.
Ad-tech sharing without consent
The OPC found Home Depot needed express opt-in before sending e-receipt details to Meta's Offline Conversions tool, a precedent reaching every brand that matches customer data to ad platforms.
Insiders and over-permissioned access
Two Shopify support employees pulled merchant order data in 2020, and broad app scopes plus agency collaborator accounts create the same kind of exposure inside your own admin.
When organisations call us
The moments that start this work
Almost every engagement begins with a dated demand from outside. The calendar matters too: code freezes from late October through Boxing Day mean serious remediation happens between June and September.
The acquirer's PCI letter
Your processor asks for the annual attestation and, under the revised SAQ A wording, wants comfort about payment-page scripts nobody on the team has ever inventoried.
An incident on checkout or accounts
A skimmer alert, an account-takeover wave against loyalty balances, or a breach notice from an email or SMS vendor forces a response overnight.
Cyber-insurance renewal
The questionnaire asks about MFA on the Shopify admin, backups and an incident plan, and nobody is confident the honest answer is yes.
Quebec or US expansion
Law 25's named person in charge, French-language notices and cookie changes, or CCPA rights for California customers, arrive with the market you just entered.
Wholesale and marketplace onboarding
Retail partners send security questionnaires and expect a policy set a founder-led brand has never needed to write.
A raise or a sale
Investors and aggregators run privacy and security due diligence, and the consent records behind your list suddenly become an asset-value question.
E-commerce & DTC Brands: privacy & security questions, answered
Yes in practice. Selling online is a commercial activity, which brings PIPEDA into play, and the law follows personal information that crosses provincial or national borders regardless of where you are headquartered. Because a typical brand's storefront, ESP, help desk and 3PL are US-hosted, customer data crosses the border constantly, so the federal rules and their breach-reporting duties are part of daily operations.
It does. The law attaches to Quebec customers' personal information, not to where the brand sits. That means naming a person in charge of personal information and publishing their title, adopting governance policies, assessing new systems and cross-border communication of data, keeping an incident register and notifying the CAI when an incident presents a risk of serious injury. The penalty regime scales to worldwide turnover, so ignoring it is not a strategy.
Shopify's own security documentation says merchants have steps to take on their own, and the acquirer's attestation request lands on you, not Ottawa. Your SAQ still has to be completed, and since the March 2025 eligibility change SAQ A merchants confirm their site is protected against attacks from scripts. Admin access, installed apps, consent management, staff accounts and everything in your marketing stack remain entirely your responsibility.
Around the freeze. Most brands lock code from late October through Boxing Day for the BFCM peak, so testing, remediation and anything touching the theme or checkout belongs between June and September. The first quarter suits consent cleanup and policy work after holiday list growth, and insurance or attestation deadlines set the rest of the calendar.
Largely, yes. Accountability under PIPEDA stays with the organization that collected the data, so a breach at a communications or engagement vendor becomes your risk assessment, your regulator notifications and your customer emails. Giant Tiger's experience shows the pattern: the compromise happened at a third party, but the brand's name was on the story. Vendor reviews, contracts and a rehearsed incident plan decide how well that day goes.
Rarely at this size. Most Canadian DTC brands have no security or privacy hire, and the responsibility sits with the COO or CFO by default. A fractional model, security leadership through a vCISO and privacy operations through a Virtual Privacy Officer, answers the acquirer, the insurer, the OPC and the CAI without adding an executive salary.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What is a vCISO, and when do you need one?
- VPO vs vCISO: do you need one, the other, or both?
- What should I do after a data breach?
- What is multi-factor authentication, and do I need it?
- How do we prepare for a customer security questionnaire?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- Building a Third-Party Vendor Risk Assessment Program That Scales
- VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.