Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Commerce & industry

Privacy & Security for E-commerce & DTC Brands

Your brand's data estate lives in software you rent: the storefront on Shopify or Lightspeed, flows in Klaviyo, pixels firing into Meta and Google, orders picked by a 3PL. Privacy Horizon builds the privacy and security program that stack needs, covering PCI's new SAQ A script expectations, Law 25's cookie and profiling duties, CASL consent and breach response, without asking you to hire a single executive.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Founder-led and Shopify Plus-tier brands headquartered in Toronto, Montreal or Vancouver, selling to consumers across Canada and the US, often shipping through an American 3PL with no in-house security or privacy staff. The person we usually meet first is the COO or CFO holding an acquirer letter or an insurance questionnaire.

Heads of e-commerce, CRM and marketing who own the Klaviyo account, the Meta and TikTok pixels, the GTM container and the consent platform, and need a straight answer on which campaigns CASL and Law 25 actually permit.

Omnichannel retailers running a few stores alongside e-com, subscription brands on Recharge-class billing, and any brand preparing for wholesale onboarding, a raise or aggregator due diligence.

Outside of Logistics Retail Warehouse With Inventory Manager Using Tablet Computer, talking to Worker Loading Delivery Truck with Cardboard Boxes, Online Orders, Food and Medicine

Services

Privacy & security services for e-commerce & dtc brands

Each service below is scoped for how e-commerce & dtc brands actually operate — their systems, their regulators and the reviews they face.

What you hold

The customer data behind a DTC storefront

An online brand holds far more than orders. Each record type below sits in a different US-hosted SaaS tool, and every one of them is yours to protect under Canadian law.

Identity, orders and shipping history

Names, addresses, purchase and delivery records spread across the storefront, the 3PL's warehouse system and EDI feeds to wholesale partners.

Marketing consent and event data

SMS numbers with consent timestamps, email lists, behavioural events and the hashed emails matched to ad platforms through CAPI and Offline Conversions.

Loyalty balances and subscription records

Points ledgers in Smile.io-class tools plus subscription and dunning records in Recharge, all attractive targets for account-takeover fraud.

Support tickets and ID scans

Gorgias and Zendesk queues holding photos, addresses and sometimes identity documents collected for age-gated goods.

Card data you never touch

Tokens sit with the payment gateway, yet your acquirer still expects an annual PCI attestation and, under the updated SAQ A criteria, comfort about the scripts on your checkout page.

Employee and HR records

Payroll, SINs and banking details for head-office staff, exactly the files ransomware crews took in recent Canadian retail incidents.

Regulatory map

The rulebook for selling online in Canada

No single regulator covers an online store. Federal privacy law, Quebec's reform, anti-spam law and the card brands each reach a different part of the stack.

PIPEDA

Selling online is a commercial activity, so PIPEDA applies, and it follows personal information across provincial and national borders. A breach creating a real risk of significant harm must be reported to the OPC and affected customers as soon as feasible, with records kept for two years.

Read our guide →

Quebec Law 25

Any brand with Quebec customers must designate a person in charge of personal information, publish that person's title, assess new systems and cross-border data flows, and keep a register of confidentiality incidents.

Primary source →

CASL

Email and SMS marketing requires express consent or a live existing business relationship, clear sender identification and an unsubscribe honoured within ten business days, with administrative monetary penalties reaching into the millions per violation.

Primary source →

PCI DSS v4.0.1 and the SAQ A change

SAQ A eligibility now includes confirming the site is protected against script attacks, and custom checkout JavaScript pushes a merchant into SAQ A-EP with Requirements 6.4.3 and 11.6.1 in scope.

Primary source →

Alberta and BC PIPA

Alberta requires notifying its Commissioner without unreasonable delay where a breach poses real risk of significant harm; BC's private-sector law has no mandatory reporting, though its OIPC strongly recommends it.

Read our guide →

CCPA and US state privacy laws

California's law reaches brands doing business there above its revenue or data-volume thresholds, granting residents rights to know, delete, correct and opt out of sale or sharing.

Primary source →

What goes wrong

How Canadian online retailers actually get hurt

The incident record in Canadian retail is public and specific. These are the patterns a brand's program has to anticipate rather than discover.

  • Checkout skimming (Magecart)

    A skimmer disguised as Google Tag Manager compromised the LCBO's online store, precisely the attack PCI's payment-page script requirements now target.

    Source →

  • Loyalty account takeover

    Credential-stuffing crews drained PC Optimum members' points using passwords reused from other services, and Loblaw's answer was to urge unique passwords.

    Source →

  • Marketing-vendor breach

    Giant Tiger's customer communications vendor was breached and millions of names, emails, phone numbers and addresses later leaked, with no payment data involved.

    Source →

  • Ransomware against the retailer

    Indigo lost its website and in-store POS for over a week while employee SINs and banking data were stolen; London Drugs closed every store as LockBit held head-office files.

    Source →

  • Ad-tech sharing without consent

    The OPC found Home Depot needed express opt-in before sending e-receipt details to Meta's Offline Conversions tool, a precedent reaching every brand that matches customer data to ad platforms.

    Source →

  • Insiders and over-permissioned access

    Two Shopify support employees pulled merchant order data in 2020, and broad app scopes plus agency collaborator accounts create the same kind of exposure inside your own admin.

    Source →

When organisations call us

The moments that start this work

Almost every engagement begins with a dated demand from outside. The calendar matters too: code freezes from late October through Boxing Day mean serious remediation happens between June and September.

  • The acquirer's PCI letter

    Your processor asks for the annual attestation and, under the revised SAQ A wording, wants comfort about payment-page scripts nobody on the team has ever inventoried.

  • An incident on checkout or accounts

    A skimmer alert, an account-takeover wave against loyalty balances, or a breach notice from an email or SMS vendor forces a response overnight.

  • Cyber-insurance renewal

    The questionnaire asks about MFA on the Shopify admin, backups and an incident plan, and nobody is confident the honest answer is yes.

  • Quebec or US expansion

    Law 25's named person in charge, French-language notices and cookie changes, or CCPA rights for California customers, arrive with the market you just entered.

  • Wholesale and marketplace onboarding

    Retail partners send security questionnaires and expect a policy set a founder-led brand has never needed to write.

  • A raise or a sale

    Investors and aggregators run privacy and security due diligence, and the consent records behind your list suddenly become an asset-value question.

E-commerce & DTC Brands: privacy & security questions, answered

Yes in practice. Selling online is a commercial activity, which brings PIPEDA into play, and the law follows personal information that crosses provincial or national borders regardless of where you are headquartered. Because a typical brand's storefront, ESP, help desk and 3PL are US-hosted, customer data crosses the border constantly, so the federal rules and their breach-reporting duties are part of daily operations.

It does. The law attaches to Quebec customers' personal information, not to where the brand sits. That means naming a person in charge of personal information and publishing their title, adopting governance policies, assessing new systems and cross-border communication of data, keeping an incident register and notifying the CAI when an incident presents a risk of serious injury. The penalty regime scales to worldwide turnover, so ignoring it is not a strategy.

Shopify's own security documentation says merchants have steps to take on their own, and the acquirer's attestation request lands on you, not Ottawa. Your SAQ still has to be completed, and since the March 2025 eligibility change SAQ A merchants confirm their site is protected against attacks from scripts. Admin access, installed apps, consent management, staff accounts and everything in your marketing stack remain entirely your responsibility.

Around the freeze. Most brands lock code from late October through Boxing Day for the BFCM peak, so testing, remediation and anything touching the theme or checkout belongs between June and September. The first quarter suits consent cleanup and policy work after holiday list growth, and insurance or attestation deadlines set the rest of the calendar.

Largely, yes. Accountability under PIPEDA stays with the organization that collected the data, so a breach at a communications or engagement vendor becomes your risk assessment, your regulator notifications and your customer emails. Giant Tiger's experience shows the pattern: the compromise happened at a third party, but the brand's name was on the story. Vendor reviews, contracts and a rehearsed incident plan decide how well that day goes.

Rarely at this size. Most Canadian DTC brands have no security or privacy hire, and the responsibility sits with the COO or CFO by default. A fractional model, security leadership through a vCISO and privacy operations through a Virtual Privacy Officer, answers the acquirer, the insurer, the OPC and the CAI without adding an executive salary.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.