Sooner or later, someone asks. A cyber insurance renewal arrives with a questionnaire. A regulator or professional college runs an audit. A patient, a client, or a big customer wants to know where their information is kept before they sign. In most offices, the honest answer is a pause, a glance around the room, and “I’d have to check.”
That answer is worth fixing, and not because anyone did anything wrong. Every one of these questions can be answered, and every year more businesses are expected to have the answers ready.
Who ends up asking
For clinics and health practices in Ontario, the framework is PHIPA, the Personal Health Information Protection Act. It holds the practice responsible for knowing where records are and who can get at them, and for telling the people affected when something goes wrong. That responsibility stays with the practice, not with its software vendors. For most other businesses, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies, and it carries its own duties. Certain breaches have to be reported to the Privacy Commissioner of Canada, the people affected have to be told, and a record of every breach gets kept either way. There’s a further wrinkle for any business that files taxes here. The Canada Revenue Agency generally expects business records to be kept in Canada unless you have written permission to keep them elsewhere. Accounting and bookkeeping practices carry that one twice over, for their own books and for every client’s records they hold.
Regulators aren’t the only ones asking. Funders ask too. Community agencies now get a security survey before a contract renews. The surveys run pages deep and cover policies, audits, incident response, and technology providers. Some even come with a note saying the organization’s Chief Information Officer should be the one filling them out. Accreditation reviews ask for an evidence binder. Cyber insurance questionnaires cover the same ground, and those answers carry legal weight. A material misstatement can void the coverage. If a control isn’t in place, the safe answer is no, along with a plan to fix it.
We wrote about the legal side in our Canadian privacy law compliance guide; this post is about the operational side.
If nobody has asked you yet
Maybe none of this has landed on your desk. No survey, no audit, nothing from the insurer beyond the renewal invoice. It’s tempting to assume this only applies to other businesses.
Most businesses hold more personal information than they think. If you employ anyone, you hold social insurance numbers, home addresses, and the banking details direct deposit runs on. A breach of those puts you in front of your staff no matter which law applies. If you have customers, you hold their information too. The federal privacy law, or a provincial equivalent, covers how nearly every business in the country handles it. Larger customers have started sending security questionnaires down their supply chains, and insurers ask more at every renewal. If nobody has asked you yet, it’s probably a matter of time, because you hold the same kinds of information as the businesses that are already being asked.
The questions your office should be able to answer
Where is your data held? All of it. Not just the obvious system. The customer records, client files, or patient charts, yes, but also email, the shared drive, the booking or practice management system, the accounting file, and the documents saved to personal OneDrive folders nobody remembers creating. Most offices find more places than they expected once they look.
Is it in Canada? If your office runs on Microsoft 365, your email and files are usually stored in Microsoft’s Canadian data centres. That depends on how your Microsoft 365 account was set up, so it’s worth confirming rather than assuming. Line-of-business systems vary widely. Some Canadian-sounding vendors store data in the United States. For health information especially, confirm where the vendor stores it before it comes up in an audit.
Who else can touch it? Every vendor with an admin login, every integration you connected years ago, every former staff member whose account was never fully closed. This is the question that trips up the most offices. If the last person who left still technically has a working login, that’s the first thing to fix.
Where is the backup, and who holds it? A backup is a second copy of everything you just inventoried, so it deserves the same questions. Where does it live, is it in Canada, and could the people who hold it read it? It should also live somewhere separate, so one incident can’t take out both copies. Microsoft 365 in particular does not back itself up the way most people assume, which is why we run backup as a separate, independently held copy.
Has anyone tested a restore? If a backup has never been restored, nobody knows whether it works. When did the office last get a file back on purpose? If no one can say, find out.
What happens when someone leaves? Accounts closed, licences recovered, mailbox handled deliberately, access reviewed. In offices that handle sensitive records, offboarding is part of protecting them.
If it went wrong tomorrow, would you even know? Many breaches go unnoticed for weeks. When one is caught early, it’s usually because someone was watching the systems and noticed a sign-in that didn’t fit. After that, the questions are urgent. What happened, what was touched, and who has to be told. Nobody can answer those in advance. What you can prepare is the plan for answering them. Who takes charge, who gets called, and where the records live.
Why nobody owns these answers
Most of those questions aren’t technical. They’re about ownership, whether anyone in the office is responsible for knowing the answer.
The surveys and questionnaires make the same split. Roughly half of their questions are about technical controls like sign-in protection, managed computers, patching, and backups. The other half are about responsibility. Is someone in charge of technology, do reviews and audits happen on a schedule, and do the records exist to prove all of it? An assessor never just asks whether a protection exists. They ask to see the paper trail.
In most offices, nobody holds either half, because holding them is a job and nobody was ever given that job. The office manager inherited pieces of it. The most computer-comfortable partner or manager inherited the rest. Both have actual jobs. Larger companies solve this by hiring a chief technology officer, a CTO, whose whole job is to sit across from an auditor, an insurer, or a worried client and answer for the setup. An office running on a handful of staff was never going to hire one, and shouldn’t.
What owning it looks like
For most offices, ownership starts with managed IT. Accounts, devices, backups, and offboarding get handled day to day by real people you can call, so the answers stay current instead of drifting out of date.
Some organizations carry more than that. Clinics answer to a college, agencies answer to a funder’s survey, firms hold client financial records. For them, we add a layer above it. A fractional CTO fills that same role for part of the time. Someone who knows where everything lives, keeps the records an assessor expects to see, and sits in the meeting when the auditor, the insurer, or the funder asks. It’s the kind of role those questionnaires assume you have. In an office this size, the role takes a few hours a year, and a fractional arrangement covers those hours without a full-time hire.
Where to start
If any of these questions made you stop, start there. Write down what you know, note what you’d have to check, and talk to us about the gaps. The first conversation is us listening to how your office actually runs. It isn’t a pitch. Then the next time someone asks where your data lives, you’ll have the answer ready.
This post is practical guidance from an IT provider, not legal advice. For how privacy law applies to your specific situation, talk to a lawyer or your privacy officer.
Dealing with this at your business?
NDLS handles managed IT, Microsoft 365, cybersecurity, and backups for businesses in Orillia, Barrie, and across Ontario, so guides like this become someone else's job.