PPCDA Glossary

A practical glossary of PPCDA terms for Canadian SaaS teams — written for operators, not lawyers.

PPCDA is a tabled federal privacy bill that emphasizes evidence, ownership, and operational alignment. This glossary explains key terms related to PPCDA’s proposed direction.

Core PPCDA Terms

DSAR

Data Subject Access Request — a user request to access, delete, or correct their data. PPCDA’s proposed direction emphasizes verifiable evidence for each step.

Evidence

Artifacts proving an action occurred: logs, exports, screenshots, deletion confirmations, access records.

Retention

The schedule defining how long data is kept. PPCDA’s proposed model emphasizes proof of automated and manual deletion.

Access Control

Role‑based permissions, MFA enforcement, privileged access restrictions, and revocation evidence.

Vendor Alignment

Proof that vendors follow your retention, access, and deletion expectations — not their defaults.

Data Mapping

A list of all systems holding customer data — internal, vendor, legacy, and archived.

Detailed Definitions

DSAR (Data Subject Access Request)

A formal request from a user asking for access to, deletion of, or correction of their personal data. PPCDA’s proposed direction emphasizes timestamped logs, verification steps, exports, deletion proof, and a full audit trail.

Evidence

Any artifact proving a compliance action occurred. Examples: deletion logs, access logs, exports, screenshots, vendor confirmations, retention enforcement logs.

Retention Schedule

A documented timeline defining how long each category of data is stored. PPCDA’s proposed model emphasizes proof of enforcement — automated deletion, manual deletion, and exception tracking.

Access Control

Permissions defining who can access which data. PPCDA’s proposed direction emphasizes evidence of MFA, role‑based access, privileged access restrictions, and revocation logs.

Vendor Alignment

Vendors would need to enforce your retention, deletion, and access expectations. PPCDA’s proposed model emphasizes evidence of alignment: deletion confirmations, access control proof, retention logs, and DSAR support.

Data Mapping

A complete list of systems holding customer data. PPCDA’s proposed direction emphasizes evidence of mapping accuracy, updates, and ownership across teams.

Audit Trail

A timestamped record of every action taken during a compliance workflow. PPCDA’s proposed model emphasizes full audit trails for DSARs, retention enforcement, vendor reviews, and access control changes.

Deletion Confirmation

Proof that data was deleted — logs, screenshots, vendor confirmations, or system‑level evidence.

Exception Tracking

Documentation for data that cannot be deleted due to legal or operational constraints. PPCDA’s proposed direction emphasizes justification and periodic review.

Security Controls

Technical safeguards protecting customer data. PPCDA’s proposed model emphasizes evidence of encryption, logging, monitoring, vulnerability management, incident response, and backup verification.

Prepare for PPCDA’s Evidence Expectations

PPCDA is a tabled federal privacy bill. Teams preparing early can strengthen evidence workflows, reduce audit friction, and align operations with the direction regulators are already moving.

Join the Waitlist