Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Commerce & industry

Privacy & Security for Logistics & Transportation Companies

Carriers, freight brokers, 3PLs and couriers run on data that regulators, border agencies and criminals all care about: driver files, ELD location logs, dashcam footage, consignee addresses and shipper rates. Because interprovincial trucking is a federal work, PIPEDA reaches even your employees' information, and CBSA's Partners in Protection program writes cybersecurity into your border privileges. Privacy Horizon builds privacy and security programs shaped around dispatch, terminals and 24/7 operations, so you can answer shippers, insurers and the OPC without slowing freight.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

We work with asset-based carriers from fifty to two thousand power units along the 401 corridor, in Quebec, Alberta and BC, plus the freight brokers, forwarders and 3PLs of twenty to five hundred staff who move their loads. Courier, final-mile and warehousing operators face the same pressures with even tighter margins.

The people who call us are owners, VPs of operations, CFOs and safety and compliance directors juggling ELD mandates, hours-of-service, Clearinghouse queries and PIP renewals; at brokerages, it is often the president or VP of carrier relations after a fraud scare or a shipper questionnaire they cannot answer.

Most fleets have one or two IT staff supporting round-the-clock dispatch, drivers on personal phones and EDI links to dozens of trading partners. Our job is to give that thin team a privacy and security program that holds up to enterprise shippers, CBSA and the OPC without adding headcount.

Fast delivery truck travelling through the city streets

Services

Privacy & security services for logistics & transportation companies

Each service below is scoped for how logistics & transportation companies actually operate — their systems, their regulators and the reviews they face.

What you hold

The data a fleet holds, from driver files to customs manifests

A transportation company's records go far beyond invoices. Each category below carries its own legal duty, and several exist only in this industry.

Driver qualification files

Licences, abstracts, medicals, drug-and-alcohol test results, SINs and work permits sit in HR drives and recruiting platforms like Tenstreet. These are among the most sensitive employee records any Canadian employer holds, and for federal carriers they fall squarely under PIPEDA.

ELD hours-of-service and GPS breadcrumbs

Every federally regulated truck carries a certified electronic logging device that records duty status, engine data and location at least hourly. That statutory data store maps where each driver has been, and it must be secured and retained with care.

Dashcam video and in-cab audio

Road-facing and driver-facing cameras capture identifiable footage of drivers and the public. The OPC has already ruled on how far in-cab recording can go, so this footage needs defined purposes, access limits and deletion timelines.

Consignee and proof-of-delivery records

Residential delivery generates names, addresses, phone numbers, signatures and doorstep photos across the TMS and driver apps. The Canada Post supplier breach showed how shipment manifests become a mass privacy incident when a partner is compromised.

Customs and eManifest data

Commercial invoices, importer numbers and pre-arrival cargo and conveyance data flow to CBSA through EDI or the eManifest Portal. Errors and outages here carry AMPS penalties and can strand trucks at the border.

Shipper contracts, rates and load data

Rate confirmations, bills of lading and load-board postings are commercially sensitive and, in the wrong hands, the raw material for double-brokering and fictitious pickups. Protecting them is cargo security as much as data security.

Regulatory map

Why privacy law reaches deeper into trucking than most industries

Interprovincial and cross-border transportation is federally regulated, which changes which laws apply and to whom. Border programs then layer written security duties on top.

PIPEDA covers your employees, not just customers

As a federal work, an interprovincial carrier's employee personal information is governed by PIPEDA — driver files, monitoring data and all. Intraprovincial operators answer instead to provincial laws in Alberta, BC and Quebec.

Read our guide →

Two OPC findings on driver surveillance

The OPC found Trimac's continuous in-cab audio recording disproportionately privacy intrusive under PIPEDA, requiring sleep-mode microphone cut-offs and need-to-know portal access, and found another carrier's constant monitoring more intrusive than necessary.

Primary source →

The Transport Canada ELD mandate

Federally regulated carriers must run ELDs certified by an accredited body under the Commercial Vehicle Drivers Hours of Service Regulations. The device is required by law, which makes securing its location data your obligation, not an option.

Primary source →

CBSA border programs with security strings attached

eManifest requires pre-arrival electronic data backed by penalties, while Partners in Protection sets minimum security requirements — including cybersecurity controls and supply-chain-partner security — documented in a profile reviewed annually and aligned with CTPAT.

Primary source →

Quebec Law 25 for terminals and 3PLs in the province

Quebec operations need a designated person in charge of personal information, an incident register, CAI notification and privacy assessments before sending data outside Quebec — which most US-hosted TMS platforms trigger.

Primary source →

Breach reporting on multiple clocks

PIPEDA requires an OPC report and individual notice as soon as feasible when a breach creates a real risk of significant harm, with records kept for two years; Alberta's PIPA and Quebec's regime run their own timelines in parallel.

Primary source →

What goes wrong

How transportation companies actually get hit

The incident record in Canadian freight is specific: ransomware against carriers and couriers, breaches arriving through EDI suppliers, and theft of the freight itself through hijacked digital identities.

  • Ransomware that stops trucks

    TFI International's Canadian courier divisions — Canpar, ICS Courier, Loomis Express and TForce — were struck in 2020 with stolen files posted online; Manitoulin Transport was attacked by Conti the same summer, and forwarder Expeditors shut down worldwide operations for weeks in 2022.

    Source →

  • A supplier's breach becomes your breach

    Canada Post's EDI supplier Commport Communications was hit by ransomware, exposing shipping manifests from 44 large shippers covering roughly 950,000 parcel recipients. Vendor risk in logistics is the shipment data itself.

    Source →

  • Cyber-enabled cargo theft

    The FBI warns that criminals phish broker and carrier accounts, take over load-board identities, post fraudulent loads, double-broker and alter bills of lading to steal freight — with Canadian load boards and GTA warehousing corridors prime targets.

    Source →

  • Driver-surveillance complaints

    A camera or telematics rollout done without limits can itself become the incident. Both OPC trucking findings began as driver complaints, not breaches, and ended with binding expectations on recording, access and retention.

    Source →

  • Payment fraud on freight money

    Business email compromise targets carrier bank-change requests, factoring arrangements and freight payments, mirroring documented Canadian cases where a spoofed executive email moved six figures before anyone verified by phone.

When organisations call us

The moments carriers and 3PLs pick up the phone

Privacy and security work in freight rarely starts from strategy. It starts from a customer demand, a border program deadline or a bad night.

  • An enterprise shipper's RFP or questionnaire

    Retail, pharma and CPG shippers increasingly ask for SOC 2 or ISO 27001 evidence, or equivalent controls, before awarding freight. A blank questionnaire response can quietly cost you the lane.

  • A PIP application or annual review

    CBSA expects a documented security profile covering cybersecurity and supply-chain-partner security. The annual review date is a hard deadline that turns vague intentions into a written program.

  • An incident or a stolen load

    A ransomware event, a fictitious pickup or a double-brokering loss through a compromised load-board account forces the question of what should have been in place — and what must be now.

  • Cyber-insurance renewal or an AI dashcam rollout

    Insurers tighten control requirements each cycle, while camera and driver-scoring deployments trigger grievances and privacy obligations the OPC's Trimac finding has already mapped.

  • A new TMS, telematics platform or EDI integration

    Migrations to systems like McLeod, TruckMate, Rose Rocket or Samsara, and new customer EDI or API connections, are the natural moment to fix access, retention and vendor terms before go-live.

  • New legal duties landing

    Law 25 obligations for Quebec operations are in force now, and the Critical Cyber Systems Protection Act received Royal Assent in June 2026 with designations for federally regulated transportation to follow.

Logistics & Transportation Companies: privacy & security questions, answered

Yes, more than most offices. Driver files include medicals, drug-test results and SINs; ELDs log every truck's position hourly; dashcams record identifiable footage; and residential deliveries generate consignee names, addresses, signatures and doorstep photos. Even pure LTL operations hold shipper contacts and driver data that PIPEDA or provincial law governs.

Generally yes. Video and audio that identifies a driver, and often passers-by, is personal information, and for a federal carrier it is regulated under PIPEDA even though the driver is your employee. The OPC's trucking findings set clear expectations: define the purpose, limit continuous recording, restrict who can view footage and set deletion timelines.

Treat them as if they do. O/Os supply licences, abstracts, insurance and banking details, and their trucks feed your telematics and ELD platforms. Whether a specific O/O relationship counts as employment or contract, you collected and hold identifiable information about them, so safeguards, retention rules and monitoring limits should apply the same way they do for company drivers.

Renewals increasingly probe MFA on email and remote access, tested backups, EDR coverage, an incident response plan and vendor oversight. For fleets, underwriters also notice dispatch continuity: whether an encrypted TMS stops trucks. Documented controls and a rehearsed plan directly affect premiums, and gaps discovered at claim time are far more expensive.

Yes. Canada's Anti-Spam Legislation covers commercial electronic messages to prospects and customers, including freight sales outreach to shippers and brokers. You need consent (express or implied through an existing business relationship), sender identification and a working unsubscribe. A simple CASL procedure for the sales team is inexpensive insurance against complaints.

Start with an assessment against what your stakeholders already demand: PIP's minimum security requirements, your largest shippers' questionnaires and your insurer's application. That produces a short, prioritized roadmap — typically MFA, EDI and portal access controls, driver-monitoring rules and an incident plan — sequenced around Q4 peak season so operations never stall.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.