
When you use a mail scanning service, you are trusting another organisation with some of your most sensitive personal information. Bank statements, CRA notices, medical correspondence, legal documents, insurance policies: all of it passes through their hands, gets scanned by their equipment, and is stored on their servers. The convenience is significant, but so is the responsibility.
In Canada, the handling of your personal information by commercial organisations is governed by the Personal Information Protection and Electronic Documents Act, commonly known as PIPEDA. Understanding what PIPEDA requires and how it applies to mail scanning services helps you evaluate whether your provider is genuinely protecting your data or just claiming to.
This article explains PIPEDA's relevance to mail scanning, the specific security measures that matter, and how to assess whether a provider meets the standard your personal information deserves.
PIPEDA is Canada's federal privacy law governing how private-sector organisations collect, use, and disclose personal information in the course of commercial activities. It applies to every commercial organisation operating in Canada that handles personal information, with certain exceptions for organisations in provinces that have substantially similar provincial legislation (Alberta, British Columbia, and Quebec have their own laws, though PIPEDA still applies to federally regulated organisations and interprovincial/international transactions).
PIPEDA is built on 10 principles that organisations must follow:
A mail scanning provider collects your personal information in multiple ways:
The volume and sensitivity of personal information a mail scanning provider handles makes PIPEDA compliance critically important. This is not a social media platform holding your email address. This is an organisation that potentially sees every piece of your personal, financial, and legal correspondence.
PIPEDA's seventh principle, Safeguards, requires organisations to protect personal information with security measures appropriate to the sensitivity of the information. For mail scanning, where the information is highly sensitive, the required standard of protection is correspondingly high.
Encryption is the foundation of digital security for scanned documents. Two types of encryption matter:
Encryption in transit: When scanned documents travel from the scanning equipment to the server, and from the server to your device, they must be encrypted. TLS 1.2 or higher (the same technology that protects online banking) prevents anyone from intercepting your documents during transmission. Look for HTTPS on your provider's website and dashboard. If their dashboard does not use HTTPS, walk away immediately.
Encryption at rest: When your scanned documents sit on the provider's servers, they must be encrypted. AES-256 encryption is the industry standard for data at rest. This means that even if someone gains physical access to the server hardware, the stored documents are unreadable without the encryption keys. Ask your provider specifically whether they encrypt stored documents and what standard they use.
Access controls determine who can see your scanned mail and under what circumstances.
Internal access controls: Within the provider's organisation, access to your scanned documents should be restricted to the minimum number of employees who need it. Not every employee should be able to view customer mail. The scanning technician needs access to operate the scanner. The support team may need access to troubleshoot issues. Management may need access for quality assurance. But the marketing team, the sales team, and other departments should not have access to customer correspondence.
Customer access controls: Your account should be protected by strong authentication:
Your mail exists in physical form before it is scanned. Physical security measures protect your mail during this vulnerable phase:
PIPEDA requires that personal information be retained only as long as necessary for the identified purpose. For mail scanning, this raises important questions:
A PIPEDA-compliant provider will have clear, documented data retention policies. They should tell you exactly how long they keep your scanned documents, give you the ability to delete documents, and confirm that data is permanently removed from all systems (including backups) when you close your account.
Knowing what PIPEDA requires is one thing. Evaluating whether your provider actually complies is another. Here are practical steps to assess a provider's data protection practices.
Every PIPEDA-compliant organisation must make their privacy practices readily available (Principle 8: Openness). Their privacy policy should clearly explain:
A vague privacy policy that uses generic language without specifics is a warning sign. "We take your privacy seriously" is meaningless without concrete details about how.
Contact the provider and ask specific questions about their security practices:
A provider that answers these questions clearly and specifically is demonstrating both competence and transparency. A provider that is evasive, vague, or dismissive is raising red flags about their actual security practices.
Independent verification of security practices is more reliable than self-attestation. Look for:
Not all providers will have these certifications, especially smaller operations. But asking about them tells you how seriously the provider takes security, and providers who have invested in third-party audits are demonstrating a higher level of commitment to data protection.
Even with strong security measures, incidents can occur. PIPEDA includes provisions for breach notification that affect how your provider must respond.
Under PIPEDA's breach notification provisions (effective since November 2018), organisations must:
Given the sensitivity of mail contents (financial data, government correspondence, medical information, legal documents), virtually any breach of a mail scanning provider's systems would create a real risk of significant harm. If your scanned CRA notices, bank statements, or medical letters were exposed, the potential for identity theft, financial fraud, and other harms is substantial.
This means your provider should have robust incident response procedures, because a breach of their systems almost certainly triggers mandatory notification obligations.
As a customer of a mail scanning service, PIPEDA gives you specific rights regarding your personal information:
You have the right to request access to all personal information the organisation holds about you. This includes your scanned documents, account information, access logs, and any other data they have collected. They must respond within 30 days and provide the information at minimal or no cost.
If your personal information is inaccurate or incomplete, you have the right to request correction.
You can withdraw your consent for the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions. In practical terms, this often means closing your account and having your data deleted.
If you believe a provider is not complying with PIPEDA, you can file a complaint with the Office of the Privacy Commissioner of Canada. The Commissioner can investigate, make recommendations, and in some cases, take the matter to Federal Court.
Use this checklist when evaluating a mail scanning provider's security and privacy practices:
It is easy to overlook security when choosing a mail scanning provider. The dashboard looks nice, the price is right, and you want to get set up quickly. But consider what is at stake. Your mail contains:
A breach of this information could enable identity theft, financial fraud, insurance fraud, and other serious harms. The cost of recovering from identity theft in Canada averages thousands of dollars and hundreds of hours. And unlike a stolen credit card, which can be cancelled and replaced, a breached collection of your personal correspondence cannot be "un-breached."
Mail scanning is a powerful convenience that replaces physical mailbox visits with instant digital access to your correspondence. But that convenience comes with a significant trust requirement. You are handing your most sensitive personal information to another organisation. PIPEDA provides a legal framework for protecting that information, but the law is only as effective as the provider's compliance with it.
Do your due diligence. Read the privacy policy. Ask hard questions. Verify security measures. Choose a provider that treats your personal information with the seriousness it deserves. Your mail is your life on paper. Make sure it is in safe hands.