Resources
Short, practical guides, Canadian privacy-law obligations, and official sources for Canadian businesses. We publish slowly and only when a guide is genuinely useful — this page is a working reference, not a news feed.
Payment Verification Policy Generator
Answer six quick questions and get a free, one-page Payment Verification Policy sized to how your business actually works — instantly, no signup required. Print it, download it, or have it emailed to you.
Generate my policy →Start with these two.
How to verify a payment-change request
A convincing email asking to update banking details is one of the most common ways small businesses lose money. The fix is a process, not software:
- Pause. Treat every request to change payment details as unverified until proven otherwise — even if it follows a real conversation.
- Find the contact yourself. Use a phone number from your own records, a signed contract, or a previous verified invoice. Never use the contact details in the request itself.
- Confirm verbally. Speak to a person you know, or who can prove who they are, before any money moves.
- Write it down. Record who confirmed the change, how, and when. Make this a step someone owns — not a favour someone does.
Build a one-page first-response contact list
When email, files, booking, or payment systems stop working, the first hour goes better if nobody has to guess. One page, printed and shared:
- Decision-maker — who has authority to act and approve spending in an incident.
- IT provider contact — the person or company who can actually touch the systems.
- Insurer and bank — policy number and fraud-line phone numbers.
- Key systems list — email, files, accounting, booking/POS, and who administers each.
- Communication owner — who tells staff, customers, or clients, and through what channel.
Construction
Draw requests and supplier banking changes: a verification checklist
Construction payments are high-value, frequent, and often time-pressured — which is exactly why verification has to be a written habit, not a judgment call:
- Treat every change as unverified. Any new banking detail, draw request, or "updated invoice" is unconfirmed until proven otherwise — even mid-project, even from a contact you know.
- Confirm by phone, using your own records. Call the number in your master agreement or last verified invoice. Never use the contact details in the request itself.
- Set a two-person rule. Choose a dollar threshold above which a second person must sign off before money moves.
- Record the confirmation. One line in the project file: who confirmed, how, and when.
- Capture details once, properly. When a new subcontractor or supplier starts, collect banking details through a verified channel and store them where the person paying can actually find them.
Health & Wellness
Before your practice adopts a new app or AI tool: six questions
Booking platforms, clinical systems, and AI features can all be helpful — but your practice stays responsible for the patient information it hands over. Ask these before anything new goes live:
- What patient or client information would this tool receive?
- Where is that information stored, and does it leave Canada?
- Who in the practice owns the account and the data in it?
- Can we export or delete our information if we stop using it?
- How would the provider tell us if they had a security incident?
- Who is our named privacy contact for questions about this tool?
This is practical operational guidance, not legal advice — where professional rules apply, confirm with your college or association.
Where problems usually start — in ordinary business processes
Most incidents we see do not begin with sophisticated attacks. They begin with everyday moments: an invoice, a password, a forgotten update, a handy new tool. These four scenarios are educational starting points, drawn from Canadian government guidance and published incident research.
A message that looks like a supplier, a manager, or a client asks for a payment, a bank-account change, or a quick favour. It can follow a real conversation and arrive at a busy moment. The request itself is the attack.
The weakness is usually not a careless employee; it is a process that lets one person approve an unusual request without verification.
A password reused across services, or exposed in an unrelated breach, can open business email, cloud storage, accounting tools, or banking. From inside an email account, an attacker can reset other passwords and make fraudulent requests look genuine.
Security updates repair known weaknesses in computers, phones, routers, browsers, and key business software. Once a weakness is public, attackers can scan broadly for organizations that have not applied the fix.
This is usually an operational problem, not a technical one: nobody owns the update routine, an old device is forgotten, or specialized software is excluded from automatic updates.
Booking, accounting, payroll, client-management, and IT-support providers may hold your client information or have privileged access to your systems. A failure at one provider can affect many of its customers at once.
Your business remains responsible for understanding where client information goes and what safeguards your providers use.
Privacy responsibilities: a practical starting point
Privacy responsibilities depend on what your business does, where it operates, what personal information it handles, and where that information travels. This overview is practical information, not legal advice.
- A privacy policy that clearly tells clients what you collect, why you collect it, and how you protect it
- Meaningful consent before collecting personal information from clients or website visitors
- A named person responsible for privacy compliance in your organization
- Reasonable security safeguards appropriate to the sensitivity of the information you hold
- A process for individuals to request access to their information and seek corrections
- Retention and secure-disposal practices tied to identified business purposes
- A documented breach response process — including assessment, records, escalation, reporting, and notification
- Records of any breaches, even those you determine don't require reporting
Authoritative Canadian references we rely on
Looking for guidance written for your kind of business? See our industry pathways for construction, health & wellness, property management, professional services, and retail & hospitality.