New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Commerce & industry
Privacy & Security for Logistics & Transportation Companies
Carriers, freight brokers, 3PLs and couriers run on data that regulators, border agencies and criminals all care about: driver files, ELD location logs, dashcam footage, consignee addresses and shipper rates. Because interprovincial trucking is a federal work, PIPEDA reaches even your employees' information, and CBSA's Partners in Protection program writes cybersecurity into your border privileges. Privacy Horizon builds privacy and security programs shaped around dispatch, terminals and 24/7 operations, so you can answer shippers, insurers and the OPC without slowing freight.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with asset-based carriers from fifty to two thousand power units along the 401 corridor, in Quebec, Alberta and BC, plus the freight brokers, forwarders and 3PLs of twenty to five hundred staff who move their loads. Courier, final-mile and warehousing operators face the same pressures with even tighter margins.
The people who call us are owners, VPs of operations, CFOs and safety and compliance directors juggling ELD mandates, hours-of-service, Clearinghouse queries and PIP renewals; at brokerages, it is often the president or VP of carrier relations after a fraud scare or a shipper questionnaire they cannot answer.
Most fleets have one or two IT staff supporting round-the-clock dispatch, drivers on personal phones and EDI links to dozens of trading partners. Our job is to give that thin team a privacy and security program that holds up to enterprise shippers, CBSA and the OPC without adding headcount.

Services
Privacy & security services for logistics & transportation companies
Each service below is scoped for how logistics & transportation companies actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Logistics & Transportation Companies
vCISO for carriers and 3PLs: security leadership that satisfies enterprise shippers, CBSA PIP requirements and insurers while dispatch runs 24/7.
Virtual Privacy Officer
Virtual Privacy Officer for Logistics & Transportation Companies
Virtual Privacy Officer for carriers and 3PLs: manage driver privacy under PIPEDA, ELD location data, dashcam footage and Law 25 across your terminals.
Penetration Testing
Penetration Testing for Logistics & Transportation Companies
Penetration testing for carriers and 3PLs: probe TMS portals, EDI endpoints, telematics back-ends and dispatcher phishing paths without stopping freight.
Incident Response Planning
Incident Response Planning for Logistics & Transportation Companies
Incident response plan for carriers and 3PLs: keep trucks moving through ransomware, stolen loads and EDI breaches, and hit every notification deadline.
Privacy & Security Policy Development
Privacy & Security Policy Development for Logistics & Transportation Companies
Privacy and security policies for carriers and 3PLs: driver-monitoring rules, ELD and dashcam retention, and data terms for broker-carrier agreements.
Privacy & Security Training
Privacy & Security Training for Logistics & Transportation Companies
Privacy and security training for carriers and 3PLs: teach dispatchers load-board fraud checks, drivers phishing defence and AP banking-change verification.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Logistics & Transportation Companies
Vendor security reviews for carriers and 3PLs: vet telematics, dashcam, load-board, EDI and factoring vendors before they put your fleet at risk.
SOC 2 Readiness
SOC 2 Readiness for Logistics & Transportation Companies
SOC 2 readiness for 3PLs, freight brokers and forwarders: scope Type I or II evidence the enterprise shippers on your RFPs are asking for.
ISO 27001 Readiness
ISO 27001 Readiness for Logistics & Transportation Companies
ISO 27001 readiness for carriers and forwarders: build an ISMS across terminals and SaaS that scores well on global shipper RFPs and PIP reviews.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Logistics & Transportation Companies
AI privacy impact assessments for fleets: review AI dashcams and driver-scoring tools against the OPC's trucking surveillance rulings before rollout.
What you hold
The data a fleet holds, from driver files to customs manifests
A transportation company's records go far beyond invoices. Each category below carries its own legal duty, and several exist only in this industry.
Driver qualification files
Licences, abstracts, medicals, drug-and-alcohol test results, SINs and work permits sit in HR drives and recruiting platforms like Tenstreet. These are among the most sensitive employee records any Canadian employer holds, and for federal carriers they fall squarely under PIPEDA.
ELD hours-of-service and GPS breadcrumbs
Every federally regulated truck carries a certified electronic logging device that records duty status, engine data and location at least hourly. That statutory data store maps where each driver has been, and it must be secured and retained with care.
Dashcam video and in-cab audio
Road-facing and driver-facing cameras capture identifiable footage of drivers and the public. The OPC has already ruled on how far in-cab recording can go, so this footage needs defined purposes, access limits and deletion timelines.
Consignee and proof-of-delivery records
Residential delivery generates names, addresses, phone numbers, signatures and doorstep photos across the TMS and driver apps. The Canada Post supplier breach showed how shipment manifests become a mass privacy incident when a partner is compromised.
Customs and eManifest data
Commercial invoices, importer numbers and pre-arrival cargo and conveyance data flow to CBSA through EDI or the eManifest Portal. Errors and outages here carry AMPS penalties and can strand trucks at the border.
Shipper contracts, rates and load data
Rate confirmations, bills of lading and load-board postings are commercially sensitive and, in the wrong hands, the raw material for double-brokering and fictitious pickups. Protecting them is cargo security as much as data security.
Regulatory map
Why privacy law reaches deeper into trucking than most industries
Interprovincial and cross-border transportation is federally regulated, which changes which laws apply and to whom. Border programs then layer written security duties on top.
PIPEDA covers your employees, not just customers
As a federal work, an interprovincial carrier's employee personal information is governed by PIPEDA — driver files, monitoring data and all. Intraprovincial operators answer instead to provincial laws in Alberta, BC and Quebec.
Two OPC findings on driver surveillance
The OPC found Trimac's continuous in-cab audio recording disproportionately privacy intrusive under PIPEDA, requiring sleep-mode microphone cut-offs and need-to-know portal access, and found another carrier's constant monitoring more intrusive than necessary.
The Transport Canada ELD mandate
Federally regulated carriers must run ELDs certified by an accredited body under the Commercial Vehicle Drivers Hours of Service Regulations. The device is required by law, which makes securing its location data your obligation, not an option.
CBSA border programs with security strings attached
eManifest requires pre-arrival electronic data backed by penalties, while Partners in Protection sets minimum security requirements — including cybersecurity controls and supply-chain-partner security — documented in a profile reviewed annually and aligned with CTPAT.
Quebec Law 25 for terminals and 3PLs in the province
Quebec operations need a designated person in charge of personal information, an incident register, CAI notification and privacy assessments before sending data outside Quebec — which most US-hosted TMS platforms trigger.
Breach reporting on multiple clocks
PIPEDA requires an OPC report and individual notice as soon as feasible when a breach creates a real risk of significant harm, with records kept for two years; Alberta's PIPA and Quebec's regime run their own timelines in parallel.
What goes wrong
How transportation companies actually get hit
The incident record in Canadian freight is specific: ransomware against carriers and couriers, breaches arriving through EDI suppliers, and theft of the freight itself through hijacked digital identities.
Ransomware that stops trucks
TFI International's Canadian courier divisions — Canpar, ICS Courier, Loomis Express and TForce — were struck in 2020 with stolen files posted online; Manitoulin Transport was attacked by Conti the same summer, and forwarder Expeditors shut down worldwide operations for weeks in 2022.
A supplier's breach becomes your breach
Canada Post's EDI supplier Commport Communications was hit by ransomware, exposing shipping manifests from 44 large shippers covering roughly 950,000 parcel recipients. Vendor risk in logistics is the shipment data itself.
Cyber-enabled cargo theft
The FBI warns that criminals phish broker and carrier accounts, take over load-board identities, post fraudulent loads, double-broker and alter bills of lading to steal freight — with Canadian load boards and GTA warehousing corridors prime targets.
Driver-surveillance complaints
A camera or telematics rollout done without limits can itself become the incident. Both OPC trucking findings began as driver complaints, not breaches, and ended with binding expectations on recording, access and retention.
Payment fraud on freight money
Business email compromise targets carrier bank-change requests, factoring arrangements and freight payments, mirroring documented Canadian cases where a spoofed executive email moved six figures before anyone verified by phone.
When organisations call us
The moments carriers and 3PLs pick up the phone
Privacy and security work in freight rarely starts from strategy. It starts from a customer demand, a border program deadline or a bad night.
An enterprise shipper's RFP or questionnaire
Retail, pharma and CPG shippers increasingly ask for SOC 2 or ISO 27001 evidence, or equivalent controls, before awarding freight. A blank questionnaire response can quietly cost you the lane.
A PIP application or annual review
CBSA expects a documented security profile covering cybersecurity and supply-chain-partner security. The annual review date is a hard deadline that turns vague intentions into a written program.
An incident or a stolen load
A ransomware event, a fictitious pickup or a double-brokering loss through a compromised load-board account forces the question of what should have been in place — and what must be now.
Cyber-insurance renewal or an AI dashcam rollout
Insurers tighten control requirements each cycle, while camera and driver-scoring deployments trigger grievances and privacy obligations the OPC's Trimac finding has already mapped.
A new TMS, telematics platform or EDI integration
Migrations to systems like McLeod, TruckMate, Rose Rocket or Samsara, and new customer EDI or API connections, are the natural moment to fix access, retention and vendor terms before go-live.
New legal duties landing
Law 25 obligations for Quebec operations are in force now, and the Critical Cyber Systems Protection Act received Royal Assent in June 2026 with designations for federally regulated transportation to follow.
Logistics & Transportation Companies: privacy & security questions, answered
Yes, more than most offices. Driver files include medicals, drug-test results and SINs; ELDs log every truck's position hourly; dashcams record identifiable footage; and residential deliveries generate consignee names, addresses, signatures and doorstep photos. Even pure LTL operations hold shipper contacts and driver data that PIPEDA or provincial law governs.
Generally yes. Video and audio that identifies a driver, and often passers-by, is personal information, and for a federal carrier it is regulated under PIPEDA even though the driver is your employee. The OPC's trucking findings set clear expectations: define the purpose, limit continuous recording, restrict who can view footage and set deletion timelines.
Treat them as if they do. O/Os supply licences, abstracts, insurance and banking details, and their trucks feed your telematics and ELD platforms. Whether a specific O/O relationship counts as employment or contract, you collected and hold identifiable information about them, so safeguards, retention rules and monitoring limits should apply the same way they do for company drivers.
Renewals increasingly probe MFA on email and remote access, tested backups, EDR coverage, an incident response plan and vendor oversight. For fleets, underwriters also notice dispatch continuity: whether an encrypted TMS stops trucks. Documented controls and a rehearsed plan directly affect premiums, and gaps discovered at claim time are far more expensive.
Yes. Canada's Anti-Spam Legislation covers commercial electronic messages to prospects and customers, including freight sales outreach to shippers and brokers. You need consent (express or implied through an existing business relationship), sender identification and a working unsubscribe. A simple CASL procedure for the sales team is inexpensive insurance against complaints.
Start with an assessment against what your stakeholders already demand: PIP's minimum security requirements, your largest shippers' questionnaires and your insurer's application. That produces a short, prioritized roadmap — typically MFA, EDI and portal access controls, driver-monitoring rules and an incident plan — sequenced around Q4 peak season so operations never stall.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What's the difference between data privacy and cybersecurity?
- How do we prepare for a customer security questionnaire?
- How can I protect my business from ransomware and phishing?
- What should I do after a data breach?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.