# Privacy Horizon > Privacy Horizon Inc. is a Canadian privacy and security consulting firm and the maker of the PHI Navigator platform. We help organizations turn privacy and security into a competitive advantage with advisory, assessments, and compliance support across 43+ jurisdictions. Privacy Horizon combines expert advisory, hands-on assessments (PIA, TRA, penetration testing), compliance preparation (SOC 2, ISO 27001, HIPAA, PIPEDA, PHIPA), and the PHI Navigator platform. Based in Toronto, Ontario, Canada; founded 2015. ## Services - [Privacy & Security Advisory](https://www.privacyhorizon.com/advisory/): Coaching, policy development, Virtual Privacy Officer (VPO), vCISO, M&A due diligence, custom training, and AI readiness. - [Privacy & Security Assessments](https://www.privacyhorizon.com/assessments/): Privacy Impact Assessments (PIA), Threat & Risk Assessments (TRA), penetration testing, and AI privacy impact assessments. - [Compliance Services](https://www.privacyhorizon.com/compliance/): Minimum Viable Privacy for rapid compliance, plus ISO 27001 / 27701 / 27018 and SOC 2 preparation. - [PHI Navigator (platform)](https://www.privacyhorizon.com/phi-navigator/): Tooling to run a privacy program: gap assessments, risk registry, training, policy templates, and incident response. - [Pricing](https://www.privacyhorizon.com/pricing/): Minimum Viable Privacy (MVP) at $5,499 CAD/yr and the Virtual Privacy Office (VPO) from $2,200 CAD/mo. ## Regulations & frameworks - [HIPAA compliance](https://www.privacyhorizon.com/hipaa-compliance/): HIPAA for organizations handling US protected health information. - [PHIPA compliance](https://www.privacyhorizon.com/phipa-compliance/): Ontario's health-information privacy law for custodians and their agents. - [PIPA compliance](https://www.privacyhorizon.com/pipa-compliance/): Provincial private-sector privacy (PIPA) compliance support. - [PIPEDA compliance](https://www.privacyhorizon.com/pipeda-compliance/): Canada's federal private-sector privacy law for commercial activities. - [ISO 27001 & SOC 2 prep](https://www.privacyhorizon.com/iso-27001-soc-2-preparation/): Readiness and preparation for ISO 27001 certification and SOC 2 audits. ## Use cases by industry - [Healthcare](https://www.privacyhorizon.com/use-cases/health-care-sector/): Protecting patient data (PHI) and meeting HIPAA/PIPEDA and provincial health privacy laws. - [Public sector](https://www.privacyhorizon.com/use-cases/public-sector/): Privacy and security for government and public-sector organizations. - [Startups & SMEs](https://www.privacyhorizon.com/use-cases/startups-smes-healthcare-technology-companies/): Scalable privacy/security programs that pass vendor assessments and earn enterprise trust. - [AI adopters](https://www.privacyhorizon.com/use-cases/organizations-implementing-ai-solutions/): AI governance, AI privacy impact assessments, and responsible-AI data practices. ## Resources - [About Privacy Horizon](https://www.privacyhorizon.com/about/): A Canadian privacy and security firm (founded 2015) serving 43+ jurisdictions. - [Answers (Q&A hub)](https://www.privacyhorizon.com/answers/): In-depth, expert answers to common privacy, cybersecurity, and compliance questions. - [FAQs](https://www.privacyhorizon.com/faqs/): Answers to common privacy, security, assessment, certification, and compliance questions. - [Insights (blog)](https://www.privacyhorizon.com/blog-categories/): Articles on data breaches, compliance, and security trends. - [Newsroom](https://www.privacyhorizon.com/news/): Press releases, partnership announcements, and media features. - [Security incident calculator](https://www.privacyhorizon.com/security-incident-calculator/): Estimate the potential cost of a security incident. - [Book a demo / contact](https://www.privacyhorizon.com/book-demo/): Talk to the team about your privacy and security needs. ## Industries we serve - [All industries](https://www.privacyhorizon.com/industries/): Privacy & security services scoped by sector. - [Privacy & Security for Dental Practices](https://www.privacyhorizon.com/industries/dental-practices/): Privacy and security for Canadian dental practices: PHIPA custodianship, RCDSO records rules, CDAnet claims data and DSO acquisition risk, handled for you. - [Privacy & Security for Physiotherapy & Chiropractic Clinics](https://www.privacyhorizon.com/industries/physiotherapy-and-chiropractic-clinics/): Privacy and security advisory for Ontario physiotherapy and chiropractic clinics: HCAI/OCF disclosures, College retention rules, and PHIPA custodian duties. - [Privacy & Security for Mental Health & Counselling Practices](https://www.privacyhorizon.com/industries/mental-health-and-counselling-practices/): Privacy and security for Canadian therapy practices: PHIPA custodian duties, CRPO record standards, AI scribe consent and Vastaamo-style breach planning. - [Privacy & Security for Pharmacies](https://www.privacyhorizon.com/industries/pharmacies/): Privacy and security for Canadian pharmacies: PHIPA custodian status, the Designated Manager, dispensing-system risk and dual OCP/IPC breach reporting. - [Privacy & Security for Medical & Diagnostic Labs](https://www.privacyhorizon.com/industries/medical-and-diagnostic-labs/): Privacy and security for medical and diagnostic labs: PHIPA custodian duties, LSCLA licensing, OLIS reporting and ISO 15189-aligned security programs. - [Privacy & Security for Medical Imaging Clinics](https://www.privacyhorizon.com/industries/medical-imaging-clinics/): Privacy and security for medical imaging clinics: PHIPA-aligned programs covering RIS/PACS, DICOM exposure, ICHSC licensing and radiology AI oversight. - [Privacy & Security for Home & Community Care Agencies](https://www.privacyhorizon.com/industries/home-and-community-care-agencies/): Privacy and security advisory for home and community care agencies: SPO contract schedules, PSW field-device controls, and CHRIS-scale access governance. - [Privacy & Security for Long-Term Care & Retirement Homes](https://www.privacyhorizon.com/industries/long-term-care-and-retirement-homes/): Privacy and security for Ontario long-term care and retirement homes: dual PHIPA custodian status, SDM access rules, and eMAR downtime planning. - [Privacy & Security for Virtual Care & Telehealth Platforms](https://www.privacyhorizon.com/industries/virtual-care-and-telehealth-platforms/): Privacy advisory for Canadian virtual care platforms: custodian vs vendor status, Ontario Health verification, and US HIPAA readiness. - [Privacy & Security for AI Scribe & Clinical AI Vendors](https://www.privacyhorizon.com/industries/ai-scribe-and-clinical-ai-vendors/): Privacy and security advisory for Canadian AI scribe and clinical AI vendors: PHIPA agent status, IPC scribe guidance, and Infoway pre-qualification support. - [Privacy & Security for Patient Engagement & Scheduling Apps](https://www.privacyhorizon.com/industries/patient-engagement-and-scheduling-apps/): Privacy and security for patient booking, portal and eReferral vendors: PHIPA agent/ESP/HINP duties, Ontario Health OAB standards, SOC 2 and HIPAA readiness. - [Privacy & Security for Medical Device Makers](https://www.privacyhorizon.com/industries/medical-device-makers/): Privacy and security advisory for Canadian medical device makers: Health Canada cybersecurity evidence, ISO 13485-aligned programs, RPM cloud compliance. - [Privacy & Security for Biotech & Pharma Companies](https://www.privacyhorizon.com/industries/biotech-and-pharma-companies/): Privacy and security advisory for Canadian biotech and pharma companies: trial data, PSP hub oversight, GCP/GMP-aligned controls, and licensing diligence. - [Privacy & Security for Clinical Research Organizations](https://www.privacyhorizon.com/industries/clinical-research-organizations/): Privacy and security advisory for Canadian CROs: sponsor qualification audits, key-coded trial data, GCP record duties, and SOC 2 or ISO 27001 evidence. - [Privacy & Security for Health Charities & Patient Organizations](https://www.privacyhorizon.com/industries/health-charities-and-patient-organizations/): Privacy and security for Canadian health charities and patient organizations: donor CRMs, PHIPA custodian status, registries and the Blackbaud pattern. - [Privacy & Security for Payment Processors & PayFacs](https://www.privacyhorizon.com/industries/payment-processors-and-payfacs/): Payment processor and PayFac privacy & security: RPAA frameworks, PCI DSS v4, FINTRAC and sponsor-bank due diligence support for Canadian PSPs. - [Privacy & Security for Online Lenders & BNPL Providers](https://www.privacyhorizon.com/industries/online-lenders-and-bnpl/): Privacy and security for online lenders and BNPL providers: Law 25 automated-decision duties, credit-bureau audits, B-10 partner reviews and breach readiness. - [Privacy & Security for Wealth Management & Robo-Advisors](https://www.privacyhorizon.com/industries/wealth-management-and-robo-advisors/): Privacy and security for wealth managers and robo-advisors: CIRO Rule 3703 reporting, NI 31-103 controls, KYC data protection and allocator DDQ readiness. - [Privacy & Security for Credit Unions & Caisses Populaires](https://www.privacyhorizon.com/industries/credit-unions-and-caisses-populaires/): Privacy and security for credit unions: FSRA IT risk readiness, member data protection, shared-core vendor risk and board-level programs from a Canadian team. - [Privacy & Security for Insurance Brokerages & MGAs](https://www.privacyhorizon.com/industries/insurance-brokerages-and-mgas/): Privacy and security for insurance brokerages and MGAs: RIBO-aligned safeguards, BMS protection, carrier-portal controls and FSRA-ready programs. - [Privacy & Security for Insurtech Companies](https://www.privacyhorizon.com/industries/insurtech-companies/): Privacy and security for insurtech companies: carrier B-10 vendor reviews, Québec's alternative-distribution rules and underwriting-AI risk in one program. - [Privacy & Security for Accounting & Bookkeeping Firms](https://www.privacyhorizon.com/industries/accounting-and-bookkeeping-firms/): Privacy and security for Canadian accounting and bookkeeping firms: PIPEDA, Law 25, CPA Rule 208 confidentiality and FINTRAC duties around tax season. - [Privacy & Security for B2B SaaS Companies](https://www.privacyhorizon.com/industries/b2b-saas-companies/): Privacy and security advisory for B2B SaaS companies selling to enterprise: SOC 2, questionnaires, vCISO and VPO support built around a multi-tenant product. - [Privacy & Security for HR Tech & Payroll Platforms](https://www.privacyhorizon.com/industries/hr-tech-and-payroll-platforms/): Privacy and security for HR tech and payroll platforms: protect SINs and banking data, meet Law 25 hiring-AI rules, and pass enterprise HR vendor reviews. - [Privacy & Security for Martech & Adtech Platforms](https://www.privacyhorizon.com/industries/martech-and-adtech-platforms/): Privacy and security for martech and adtech platforms: prove consent under CASL, meet Law 25 default-off tracking rules, and clear brand vendor reviews. - [Privacy & Security for Edtech Platforms](https://www.privacyhorizon.com/industries/edtech-platforms/): Privacy and security for edtech platforms selling to Canadian school boards: MFIPPA/FOIPPA-ready contracts, PPM 164, and post-PowerSchool vendor terms. - [Privacy & Security for Proptech & Real Estate Software](https://www.privacyhorizon.com/industries/proptech-and-real-estate-software/): Privacy and security for Canadian proptech: tenant screening, PAD payments, MLS data feeds and REIT vendor reviews, handled inside your build cycle. - [Privacy & Security for Legaltech Companies](https://www.privacyhorizon.com/industries/legaltech-companies/): Privacy and security for legaltech companies: pass law-firm cloud due diligence, meet FLSC confidentiality duties, and ship AI drafting features safely. - [Privacy & Security for MSPs & IT Consultancies](https://www.privacyhorizon.com/industries/msps-and-it-consultancies/): Privacy and security for MSPs and IT consultancies: prove your own controls to insurers, auditors and the clients whose networks you hold the keys to. - [Privacy & Security for AI Startups & LLM App Builders](https://www.privacyhorizon.com/industries/ai-startups-and-llm-app-builders/): Privacy and security for AI startups and LLM app builders: pass enterprise AI security reviews, meet Law 25 cross-border PIA duties, and answer OPC scrutiny. - [Privacy & Security for Law Firms](https://www.privacyhorizon.com/industries/law-firms/): Privacy and security for Canadian law firms: law society rules, privilege, trust accounts and client security reviews, supported by one Toronto-based team. - [Privacy & Security for Consulting & Advisory Firms](https://www.privacyhorizon.com/industries/consulting-and-advisory-firms/): Privacy and security for consulting firms: pass OSFI B-10 client reviews, RFP security schedules and Law 25 duties without stalling client delivery. - [Privacy & Security for Staffing & Recruiting Agencies](https://www.privacyhorizon.com/industries/staffing-and-recruiting-agencies/): Privacy and security for staffing and recruiting agencies: protect candidate identity data, meet Ontario ESA and AI-disclosure rules, and pass client reviews. - [Privacy & Security for Marketing Agencies](https://www.privacyhorizon.com/industries/marketing-agencies/): Privacy and security for marketing agencies: protect client ad accounts and lists, meet CASL and Law 25, and clear enterprise vendor reviews with confidence. - [Privacy & Security for Municipalities](https://www.privacyhorizon.com/industries/municipalities/): Privacy and security for municipalities: MFIPPA's 2027 PIA and breach duties, ransomware resilience, water and transit OT, and advice council can approve. - [Privacy & Security for School Boards & K-12 Schools](https://www.privacyhorizon.com/industries/school-boards-and-k-12/): School board privacy and security: MFIPPA 2027 readiness, O. Reg. 51/26 maturity assessments, O. Reg. 52/26 edtech notices, post-PowerSchool vendor oversight. - [Privacy & Security for Colleges & Universities](https://www.privacyhorizon.com/industries/colleges-and-universities/): Privacy and security consulting for Canadian colleges and universities: FIPPA PIAs, RROSH breach reporting, O. Reg. 51/26 readiness and research security. - [Privacy & Security for Public Agencies & Crown Corporations](https://www.privacyhorizon.com/industries/public-agencies-and-crown-corporations/): Privacy and security for Canadian Crown corporations and public agencies: Privacy Act and FIPPA duties, GO-ITS 25.0 alignment, and board-ready programs. - [Privacy & Security for Charities & Foundations](https://www.privacyhorizon.com/industries/charities-and-foundations/): Privacy and security for Canadian charities and foundations: donor CRMs, CRA records, Law 25, CASL and vendor breaches like Blackbaud, handled practically. - [Privacy & Security for Member Associations & Professional Regulators](https://www.privacyhorizon.com/industries/member-associations-and-professional-regulators/): Privacy and security for member associations and professional regulators: FIPPA, PIPA, RHPA s. 36, public registers, exam records and AMS platforms. - [Privacy & Security for E-commerce & DTC Brands](https://www.privacyhorizon.com/industries/ecommerce-and-dtc-brands/): Privacy and security for e-commerce and DTC brands: Law 25 cookie rules, CASL consent, SAQ A changes and Magecart defence for Canadian online retailers. - [Privacy & Security for Hospitality & Hotels](https://www.privacyhorizon.com/industries/hospitality-and-hotels/): Privacy and security for hotels and resorts: PMS and OTA risk, PCI scope from front desk to booking engine, Law 25 and Ontario's 2026 guest-register rules. - [Privacy & Security for Real Estate Brokerages](https://www.privacyhorizon.com/industries/real-estate-brokerages/): Privacy and security for real estate brokerages in Canada: FINTRAC ID records, TRESA retention, deposit fraud defences and practical safeguards for agents. - [Privacy & Security for Construction & Engineering Firms](https://www.privacyhorizon.com/industries/construction-and-engineering-firms/): Privacy and security for construction and engineering firms: protect drawings, bids and progress payments, and clear PSPC, Controlled Goods and CPCSC screening. - [Privacy & Security for Manufacturers & Industrial IoT](https://www.privacyhorizon.com/industries/manufacturers-and-industrial-iot/): Privacy and security for Canadian manufacturers: IT/OT zoning, OEM security questionnaires, CMMC and CPCSC flow-downs, and ransomware that stops production. - [Privacy & Security for Logistics & Transportation Companies](https://www.privacyhorizon.com/industries/logistics-and-transportation-companies/): Privacy and security for Canadian carriers, 3PLs and couriers: PIPEDA driver data, ELD and dashcam rules, PIP cybersecurity and cargo-theft defences. ## Answers (Q&A) - [How much does SOC 2 cost and how long does it take?](https://www.privacyhorizon.com/answers/how-much-does-soc-2-cost-and-how-long-does-it-take/): How much does SOC 2 cost and how long does it take? Learn the real cost drivers — readiness vs audit fees, scope, Type I vs Type II — and a realistic timeline. - [What documents and evidence do you need for a SOC 2 audit?](https://www.privacyhorizon.com/answers/what-documents-and-evidence-do-you-need-for-a-soc-2-audit/): What documents and evidence do you need for a SOC 2 audit? A plain-language checklist of policies, system descriptions, and proof your controls operate. - [What are the most common gaps found in a SOC 2 readiness assessment?](https://www.privacyhorizon.com/answers/what-are-the-most-common-gaps-in-a-soc-2-readiness-assessment/): The most common gaps found in a SOC 2 readiness assessment — missing policies, access controls, evidence, vendor reviews, and monitoring — and how to close them. - [Can you get ISO 27001 certified without an internal security team?](https://www.privacyhorizon.com/answers/can-you-get-iso-27001-certified-without-an-internal-security-team/): Can you get ISO 27001 certified without an internal security team? Yes. Learn what the standard requires, how to fill the gap, and what a vCISO does. - [What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?](https://www.privacyhorizon.com/answers/what-is-involved-in-a-pia-inputs-timeline-and-cost/): What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product. - [When should you do a Privacy Impact Assessment in the product development lifecycle?](https://www.privacyhorizon.com/answers/when-should-you-do-a-pia-in-product-development/): When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes. - [Does a SaaS company need a PIA before selling to healthcare?](https://www.privacyhorizon.com/answers/does-a-saas-company-need-a-pia-before-selling-to-healthcare/): Does a SaaS company need a PIA before selling to healthcare? Usually yes - hospitals and clinics typically require one. Here's when, why, and what's involved. - [What privacy and security assessments are required before selling to government?](https://www.privacyhorizon.com/answers/what-assessments-are-required-before-selling-to-government/): What privacy and security assessments are required before selling to government? A plain-language guide to PIAs, TRAs, SOC 2/ISO 27001, and pen tests in Canada. - [Do you need a TRA before moving sensitive data to a new cloud provider?](https://www.privacyhorizon.com/answers/do-you-need-a-tra-before-moving-sensitive-data-to-a-new-cloud/): Do you need a TRA before moving sensitive data to a new cloud provider? When it's required, what it covers, and how it differs from a PIA — explained plainly. - [What is a vCISO, and when do you need one?](https://www.privacyhorizon.com/answers/what-is-a-vciso-and-when-do-you-need-one/): What is a vCISO, and when do you need one? A vCISO is a part-time, outsourced security leader. Learn what they do and the signs your organization needs one. - [How much does a Virtual Privacy Officer (VPO) cost?](https://www.privacyhorizon.com/answers/how-much-does-a-virtual-privacy-officer-cost/): How much does a Virtual Privacy Officer (VPO) cost? Privacy Horizon's VPO starts at CAD $2,200/month. Learn the cost drivers and how to get a tailored quote. - [Virtual Privacy Officer vs privacy lawyer: which do you need?](https://www.privacyhorizon.com/answers/vpo-vs-privacy-lawyer-which-do-you-need/): Virtual Privacy Officer vs privacy lawyer: which do you need? Compare what each role does, when to use one or both, and how they work together on compliance. - [How much does a vCISO cost?](https://www.privacyhorizon.com/answers/how-much-does-a-vciso-cost/): How much does a vCISO cost? Learn the pricing models (retainer, project, fractional), what drives the price, and how a virtual CISO compares to a full-time hire. - [vCISO vs a managed IT security provider: what's the difference?](https://www.privacyhorizon.com/answers/vciso-vs-managed-it-security-provider/): vCISO vs a managed IT security provider: a vCISO leads security strategy and owns risk; an MSSP runs tools and monitoring. Learn the difference and which you need. - [VPO vs vCISO: do you need one, the other, or both?](https://www.privacyhorizon.com/answers/vpo-vs-vciso-do-you-need-one-or-both/): VPO vs vCISO: do you need one, the other, or both? Compare what each role owns, where they overlap, and how to decide based on your data, risks, and obligations. - [How does a startup pass an enterprise vendor security review?](https://www.privacyhorizon.com/answers/how-does-a-startup-pass-an-enterprise-vendor-security-review/): How does a startup pass an enterprise vendor security review? Map the buyer's requirements, close real gaps, gather evidence, and lead with a SOC 2 or ISO 27001 report. - [How do you prepare for a hospital or healthcare vendor security and privacy review?](https://www.privacyhorizon.com/answers/how-to-prepare-for-a-hospital-vendor-security-and-privacy-review/): How to prepare for a hospital or healthcare vendor security and privacy review: data mapping, PHIPA safeguards, evidence, PIA support, and the documents reviewers expect. - [How do you assess the privacy and security risk of an AI vendor?](https://www.privacyhorizon.com/answers/how-to-assess-the-privacy-and-security-risk-of-an-ai-vendor/): How do you assess the privacy and security risk of an AI vendor? A framework covering data use, training, hosting, contracts, and security evidence. - [Do you need an AI policy before employees use ChatGPT?](https://www.privacyhorizon.com/answers/do-you-need-an-ai-policy-before-employees-use-chatgpt/): Do you need an AI policy before employees use ChatGPT? Yes — here's why, what the policy must cover, and how to roll it out without blocking productivity. - [When do you need an AI Privacy Impact Assessment (AI-PIA)?](https://www.privacyhorizon.com/answers/when-do-you-need-an-ai-pia/): When do you need an AI Privacy Impact Assessment (AI-PIA)? The triggers, timing, and how an AI-PIA differs from a standard PIA — explained in plain language. - [Can you use AI scribes in healthcare while protecting PHI?](https://www.privacyhorizon.com/answers/can-you-use-ai-scribes-in-healthcare-while-protecting-phi/): Can you use AI scribes in healthcare while protecting PHI? Yes, with patient consent, vendor due diligence, an AI-PIA, and the right safeguards. Here's how. - [Does a small business need an AI governance framework?](https://www.privacyhorizon.com/answers/does-a-small-business-need-an-ai-governance-framework/): Does a small business need an AI governance framework? Yes if it uses or builds AI. Learn what to put in place, when, and how to keep it proportionate. - [When should you hire a privacy breach response consultant?](https://www.privacyhorizon.com/answers/when-should-you-hire-a-breach-response-consultant/): When should you hire a privacy breach response consultant? Hire one the moment you suspect a breach, lack in-house expertise, or want a retainer ready first. - [Do you need an incident response plan, and what should it include?](https://www.privacyhorizon.com/answers/do-you-need-an-incident-response-plan-and-what-should-it-include/): Do you need an incident response plan, and what should it include? Yes — here are the six core components every plan needs and why regulators and buyers expect one. - [How much does a penetration test cost (and what affects the price)?](https://www.privacyhorizon.com/answers/how-much-does-a-penetration-test-cost/): How much does a penetration test cost and what affects the price? Understand the scope, depth, and methodology factors that drive pen test pricing in Canada. - [What is privacy and security due diligence in an acquisition?](https://www.privacyhorizon.com/answers/what-is-privacy-and-security-due-diligence-in-an-acquisition/): What is privacy and security due diligence in an acquisition? It is the review of a target's data practices, compliance, and cyber risk before you buy. - [Is a SOC 2 report enough to prove an acquisition target is secure?](https://www.privacyhorizon.com/answers/is-a-soc-2-report-enough-to-prove-an-acquisition-target-is-secure/): Is a SOC 2 report enough to prove an acquisition target is secure? No — here is what a SOC 2 covers, what it misses, and how to fill the gaps in M&A. - [What is a HIPAA security risk assessment, and do you need one?](https://www.privacyhorizon.com/answers/what-is-a-hipaa-security-risk-assessment-and-do-you-need-one/): What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it. - [What is PIPEDA, and does it apply to my business?](https://www.privacyhorizon.com/answers/does-pipeda-apply-to-my-business/): What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do. - [How can I protect my personal and business information from cyberattacks?](https://www.privacyhorizon.com/answers/how-to-protect-your-business-from-cyberattacks/): A practical, layered approach to protecting personal and business information from cyberattacks: MFA, patching, backups, training, and a tested incident plan. - [What should I do after a data breach?](https://www.privacyhorizon.com/answers/what-to-do-after-a-data-breach/): The steps to take after a data breach: contain it, investigate scope, meet your legal notification obligations (PIPEDA, GDPR, HIPAA), remediate, and document everything. - [How can I protect my business from ransomware and phishing?](https://www.privacyhorizon.com/answers/how-to-protect-against-ransomware-and-phishing/): Defend against ransomware and phishing with immutable backups, patching, MFA, email filtering, least privilege, network segmentation, and staff training. - [What is multi-factor authentication, and do I need it?](https://www.privacyhorizon.com/answers/what-is-multi-factor-authentication/): Multi-factor authentication (MFA) adds a second proof of identity beyond your password. Learn how it works, the strongest types, and why every business should use it. - [What's the difference between data privacy and cybersecurity?](https://www.privacyhorizon.com/answers/data-privacy-vs-cybersecurity/): Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap. - [What is SOC 2, and does my business need it?](https://www.privacyhorizon.com/answers/what-is-soc-2-and-do-i-need-it/): SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one. - [What is the difference between SOC 2 Type I and Type II?](https://www.privacyhorizon.com/answers/soc-2-type-1-vs-type-2/): SOC 2 Type I assesses control design at a point in time; Type II tests operating effectiveness over months. Compare the two, plus typical timeline and cost drivers. - [SOC 2 vs ISO 27001 — which should we pursue first?](https://www.privacyhorizon.com/answers/soc-2-vs-iso-27001/): SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both. - [Does HIPAA apply to my software or business?](https://www.privacyhorizon.com/answers/does-hipaa-apply-to-my-business/): HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business. - [Does GDPR apply to my business if we're outside Europe?](https://www.privacyhorizon.com/answers/does-gdpr-apply-outside-europe/): The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do. - [How do we prepare for a customer security questionnaire?](https://www.privacyhorizon.com/answers/how-to-prepare-for-a-security-questionnaire/): Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner. - [What is a cybersecurity risk assessment, and how often should we do one?](https://www.privacyhorizon.com/answers/how-often-cybersecurity-risk-assessment/): A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change. - [PIA vs TRA: which assessment do you need (or do you need both)?](https://www.privacyhorizon.com/answers/pia-vs-tra-which-assessment-do-you-need/): PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both. ## Latest articles - [A Month in the Life of a Virtual Privacy Officer](https://www.privacyhorizon.com/blog/a-month-in-the-life-of-a-virtual-privacy-officer/): A behind-the-scenes look at what a Virtual Privacy Officer actually does week to week — from breach triage to vendor reviews, board updates, and the quiet work that keeps you compliant. - [A PIA Across the Product Lifecycle: From Design to Evergreen](https://www.privacyhorizon.com/blog/a-pia-across-the-product-lifecycle/): A practical guide to running a privacy impact assessment as a living thread through the product lifecycle — from early design choices to a launch-ready report to an evergreen version you keep current. - [A Right-Sized AI Governance Framework for Small & Mid-Sized Businesses](https://www.privacyhorizon.com/blog/a-right-sized-ai-governance-framework-for-smbs/): AI governance for an SMB doesn't have to mean a 40-page policy nobody reads. Here's a practical, right-sized framework you can stand up in weeks, not quarters. - [Conducting an AI PIA in Healthcare: A Practical Walkthrough](https://www.privacyhorizon.com/blog/ai-pia-in-healthcare-a-walkthrough/): A step-by-step, plain-language walkthrough of how to run an AI privacy impact assessment in a Canadian healthcare setting — from scoping to data flows, AI-specific risks, and sign-off. - [AI Scribes in Healthcare: Efficiency Without Exposing PHI](https://www.privacyhorizon.com/blog/ai-scribes-in-healthcare-efficiency-without-exposing-phi/): AI scribes can give clinicians hours back each week, but they also route patient conversations through new vendors and models. Here is how to capture the efficiency without exposing PHI. - [An AI Vendor Privacy & Security Checklist for Procurement Teams](https://www.privacyhorizon.com/blog/ai-vendor-privacy-security-checklist-for-procurement/): A practical, plain-language checklist procurement teams can use to vet AI vendors on data handling, model training, security posture, and contract terms before signing. - [Before You Move Sensitive Data to a New Cloud: The Case for a TRA](https://www.privacyhorizon.com/blog/before-you-move-sensitive-data-to-a-new-cloud/): A cloud migration moves your most sensitive data into someone else's infrastructure. A Threat Risk Assessment is how you decide, with evidence, whether that move is safe. - [Building a Third-Party Vendor Risk Assessment Program That Scales](https://www.privacyhorizon.com/blog/building-a-third-party-vendor-risk-assessment-program/): A practical playbook for a vendor risk program that tiers vendors by risk, reuses evidence, and keeps pace with growth instead of buckling under it. - [Can Your Team Put Customer or Patient Data Into Generative AI? Drawing the Line](https://www.privacyhorizon.com/blog/can-your-team-put-customer-data-into-generative-ai/): Your staff are already pasting work into ChatGPT. Here is a practical framework for deciding what data can and cannot go into generative AI tools, with sharper rules for healthcare and personal information. - [The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25](https://www.privacyhorizon.com/blog/canadian-privacy-law-landscape-2026/): A plain-language map of Canada's privacy laws in 2026 — how PIPEDA, the provincial health acts, and Quebec's Law 25 fit together, and what each one actually asks of your organization. - [The First 24 Hours After a Privacy Breach: A Canadian Response Playbook](https://www.privacyhorizon.com/blog/first-24-hours-after-a-privacy-breach/): A calm, hour-by-hour playbook for Canadian organizations: how to contain a privacy breach, assess real risk of significant harm, and meet PIPEDA and provincial reporting duties without making things worse. - [How a Startup Passes Its First Enterprise Vendor Security Review](https://www.privacyhorizon.com/blog/how-a-startup-passes-its-first-enterprise-vendor-security-review/): The first enterprise deal often stalls in security review, not pricing. Here is how an early-stage company turns a daunting vendor assessment into a deal it can actually close. - [How Canadian Startups Should Sequence SOC 2 Around Their First Enterprise Deal](https://www.privacyhorizon.com/blog/how-canadian-startups-should-sequence-soc-2/): A practical playbook for Canadian startups: how to sequence SOC 2 readiness, the audit, and the observation window around a first enterprise deal so the report lands when the buyer needs it. - [How Often Should You Pen Test Your Web App?](https://www.privacyhorizon.com/blog/how-often-should-you-pen-test-your-web-app/): There is no single "right" cadence for penetration testing. The honest answer depends on what your app does, how fast it changes, and who is asking you to prove it's secure. - [Letting Your vCISO Run SOC 2 and ISO 27001 Readiness](https://www.privacyhorizon.com/blog/letting-your-vciso-run-soc-2-and-iso-27001-readiness/): A practical look at how a virtual CISO turns SOC 2 and ISO 27001 readiness from a stalled side project into a steady, audit-ready program — without a full-time hire. - [Life After the Audit: Building Continuous Compliance](https://www.privacyhorizon.com/blog/life-after-the-audit-continuous-compliance/): A SOC 2 report is a snapshot, not a finish line. Here is how to turn a one-time audit into a continuous compliance program that holds up year after year. - [PIA vs TRA: Why Many Projects Need Both](https://www.privacyhorizon.com/blog/pia-vs-tra-why-many-projects-need-both/): A PIA and a TRA answer different questions, and most projects that touch personal data need both. Here's how they fit together and where teams go wrong. - [PIPEDA Breach Notification and Record-Keeping: What to Get Right](https://www.privacyhorizon.com/blog/pipeda-breach-notification-and-record-keeping/): A plain-language guide to PIPEDA's breach rules: the "real risk of significant harm" test, who and when to notify, and the breach log every organization must keep. - [Privacy and Cyber Due Diligence Before You Acquire a Company](https://www.privacyhorizon.com/blog/privacy-and-cyber-due-diligence-before-you-acquire/): A practical guide for acquirers: what privacy and cyber due diligence actually uncovers, the red flags that should change your offer, and how to avoid inheriting someone else's breach. - [The Privacy and Security Problems That Quietly Erode Deal Value](https://www.privacyhorizon.com/blog/privacy-and-security-problems-that-erode-deal-value/): Few deals collapse over a headline breach. Most lose value to quiet privacy and security gaps that surface in diligence and reprice the deal. Here is what to watch for. - [Selling to Canadian Government? The Assessments Buyers Expect](https://www.privacyhorizon.com/blog/selling-to-canadian-government-assessments-buyers-expect/): Canadian government buyers expect specific privacy and security assessments before they buy. Here's what a PIA, a TRA, and supporting evidence prove, and how to be ready. - [SOC 2 or ISO 27001 First? A Decision Framework for Canadian Scale-ups](https://www.privacyhorizon.com/blog/soc-2-or-iso-27001-first-decision-framework/): SOC 2 and ISO 27001 both prove your security maturity, but starting with the wrong one wastes months and budget. Here's how Canadian scale-ups choose. - [The SOC 2 Readiness Gaps We See Most Often (and How to Close Them)](https://www.privacyhorizon.com/blog/the-soc-2-readiness-gaps-we-see-most-often/): The same handful of gaps stall most first-time SOC 2 audits. Here are the ones our readiness assessments surface again and again, and how to close each one before your audit window opens. - [vCISO vs Your MSSP: Why a Managed Provider Isn't a Security Strategy](https://www.privacyhorizon.com/blog/vciso-vs-your-mssp/): An MSSP runs your tools. A vCISO decides what those tools should be. Here's why outsourcing operations doesn't give you a security strategy, and how the two roles fit together. - [VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program](https://www.privacyhorizon.com/blog/vpo-vciso-or-both-outsourcing-privacy-and-security/): A plain-language guide to deciding between a Virtual Privacy Officer, a virtual CISO, or both — and how to outsource privacy and security leadership without losing accountability. - [Vulnerability Scan vs Penetration Test: Why You Probably Need Both](https://www.privacyhorizon.com/blog/vulnerability-scan-vs-penetration-test/): A vulnerability scan and a penetration test sound interchangeable, but they answer different questions. Here is how to tell them apart and why most organizations need both. - [What a SaaS Vendor Needs Before Selling Into Canadian Healthcare](https://www.privacyhorizon.com/blog/what-a-saas-vendor-needs-to-sell-into-canadian-healthcare/): Canadian hospitals and health authorities run rigorous privacy and security reviews before any SaaS tool touches patient data. Here is what they expect, and how to be ready. - [VPO, Privacy Lawyer, or DIY: Who Should Own Privacy in a Growing Company](https://www.privacyhorizon.com/blog/who-should-own-privacy-in-a-growing-company/): As a company grows, privacy stops being a side task and needs a clear owner. Here is how to decide between a virtual privacy officer, a privacy lawyer, and keeping it in-house. - [Writing an AI Acceptable-Use Policy: A Practical Walkthrough](https://www.privacyhorizon.com/blog/writing-an-ai-acceptable-use-policy/): A step-by-step guide to drafting an AI acceptable-use policy your team will actually follow: scope, tiered tools, data rules, accountability, and keeping it current. - [Writing an Incident Response Plan Your Team Will Actually Use](https://www.privacyhorizon.com/blog/writing-an-incident-response-plan/): Most incident response plans fail the moment they're needed. Here's how to write one your team will actually reach for at 2 a.m. — practical, role-based, and tested.