A practical glossary of PPCDA terms for Canadian SaaS teams — written for operators, not lawyers.
PPCDA is a tabled federal privacy bill that emphasizes evidence, ownership, and operational alignment. This glossary explains key terms related to PPCDA’s proposed direction.
Data Subject Access Request — a user request to access, delete, or correct their data. PPCDA’s proposed direction emphasizes verifiable evidence for each step.
Artifacts proving an action occurred: logs, exports, screenshots, deletion confirmations, access records.
The schedule defining how long data is kept. PPCDA’s proposed model emphasizes proof of automated and manual deletion.
Role‑based permissions, MFA enforcement, privileged access restrictions, and revocation evidence.
Proof that vendors follow your retention, access, and deletion expectations — not their defaults.
A list of all systems holding customer data — internal, vendor, legacy, and archived.
A formal request from a user asking for access to, deletion of, or correction of their personal data. PPCDA’s proposed direction emphasizes timestamped logs, verification steps, exports, deletion proof, and a full audit trail.
Any artifact proving a compliance action occurred. Examples: deletion logs, access logs, exports, screenshots, vendor confirmations, retention enforcement logs.
A documented timeline defining how long each category of data is stored. PPCDA’s proposed model emphasizes proof of enforcement — automated deletion, manual deletion, and exception tracking.
Permissions defining who can access which data. PPCDA’s proposed direction emphasizes evidence of MFA, role‑based access, privileged access restrictions, and revocation logs.
Vendors would need to enforce your retention, deletion, and access expectations. PPCDA’s proposed model emphasizes evidence of alignment: deletion confirmations, access control proof, retention logs, and DSAR support.
A complete list of systems holding customer data. PPCDA’s proposed direction emphasizes evidence of mapping accuracy, updates, and ownership across teams.
A timestamped record of every action taken during a compliance workflow. PPCDA’s proposed model emphasizes full audit trails for DSARs, retention enforcement, vendor reviews, and access control changes.
Proof that data was deleted — logs, screenshots, vendor confirmations, or system‑level evidence.
Documentation for data that cannot be deleted due to legal or operational constraints. PPCDA’s proposed direction emphasizes justification and periodic review.
Technical safeguards protecting customer data. PPCDA’s proposed model emphasizes evidence of encryption, logging, monitoring, vulnerability management, incident response, and backup verification.
PPCDA is a tabled federal privacy bill. Teams preparing early can strengthen evidence workflows, reduce audit friction, and align operations with the direction regulators are already moving.
Join the Waitlist