By
Adam Simmons
· Last checked
August 2026
A data processing agreement is the piece of paper that says what a software vendor is allowed to do with your clients' information, what it is not allowed to do, and what happens when something goes wrong. It exists because your responsibility for that information does not transfer to the vendor when the information does.
Ontario's health privacy act is direct about that. A custodian "shall take steps that are reasonable in the circumstances to ensure that no agent of the custodian collects, uses, discloses, retains or disposes of personal health information" improperly, and shall "remain responsible for any personal health information that is collected, used, disclosed, retained or disposed of by the custodian's agents, regardless" (PHIPA, s. 17(3)).
That is the whole reason the document exists. You stay accountable; the agreement is how you show you took reasonable steps.
A data processing agreement is the piece of paper that says what a software vendor is allowed to do with your clients' information, what it is not allowed to do, and what happens when something goes wrong. It exists because your responsibility for that information does not transfer to the vendor when the information does.
Ontario's health privacy act is direct about that. A custodian "shall take steps that are reasonable in the circumstances to ensure that no agent of the custodian collects, uses, discloses, retains or disposes of personal health information" improperly, and shall "remain responsible for any personal health information that is collected, used, disclosed, retained or disposed of by the custodian's agents, regardless" (PHIPA, s. 17(3)).
That is the whole reason the document exists. You stay accountable; the agreement is how you show you took reasonable steps.
What does the regulation actually require of a vendor?
Ontario's regulation draws a line between two kinds of supplier, and the line matters because the obligations differ.
A supplier of electronic services to one custodian. The regulation prescribes that such a person "shall not use any personal health information to which it has access in the course of providing the services for the health information custodian except as necessary in the course of providing the services," "shall not disclose any personal health information to which it has access," and "shall not permit its employees or any person acting on its behalf to be able to have access to the information unless the employee or person acting on its behalf agrees to comply with the restrictions" (O. Reg. 329/04, s. 6(1)).
A health information network provider — defined as one who provides services "to two or more health information custodians where the services are provided primarily to custodians to enable the custodians to use electronic means to disclose personal health information to one another" (s. 6(2)).
The second category carries a longer list, and it is worth reading because it describes what a thorough agreement looks like even where it is not strictly required. Such a provider shall notify custodians "at the first reasonable opportunity" of unauthorised access; provide "a plain language description of the services"; make that description public; keep and make available "an electronic record of... all accesses"; perform "an assessment of the services... with respect to threats, vulnerabilities and risks"; ensure any third party it retains agrees to comparable restrictions; and "enter into a written agreement with each health information custodian" describing the services, "the administrative, technical and physical safeguards relating to the confidentiality and security of the information," and requiring compliance with the Act (s. 6(3)).
Which category a given product falls into is a legal characterisation, not a marketing one, and it is not always obvious. Whether the tools in your practice sit in one, the other or neither is a question for a privacy lawyer if it matters to you.
What your College asks for, separately from the statute
Two regulators put the agreement itself in their standards, which means a missing one is a professional problem as well as a legal one.
Ontario psychology: "When using an electronic record management service, even if hosted externally, the registrant must ensure the service operator acts in compliance with legislation. The HIC remains responsible for information collection, use, disclosure, and secure destruction by the agent" (CPBAO Standard 9.5(b)).
Alberta psychology is the most specific about the paperwork. A psychologist who places information into an electronic record not under their own direct custody and control "shall have a written information management agreement" covering the security requirements, "and a written information sharing agreement that addresses access, secondary use and disclosure of client information," or else "shall have confidence that the person or organization that has primary responsibility for the record has reasonable access and privacy protections in place" (CAP §7.7).
Two agreements, not one — what they may do with the information, and who may see it. Most vendor documents cover the first and are vague about the second.
Why does this determine whether using a vendor is a "disclosure"?
This is the part that makes the agreement worth more than filing convenience.
The regulation provides that a custodian who uses such services "shall not be considered in so doing to make the information available or to release it to that person for the purposes of the definition of 'disclose'" — but only "if the person complies with subsections (1) and (3), to the extent that either is applicable" (s. 6(4)).
Read the condition. Using a vendor is not treated as disclosing client information provided the vendor behaves in the prescribed way. The agreement is how you know they have committed to.
Quebec makes the written agreement explicit
Quebec's private-sector act ties the agreement directly to sending information out of the province: "The communication of the information must be the subject of a written agreement that takes into account, in particular, the results of the assessment and, if applicable, the terms agreed on to mitigate the risks identified in the assessment" (P-39.1, s. 17).
What a usable agreement contains
Strip away the boilerplate and six things matter.
Purpose limitation. The vendor uses client information only to deliver the service to you. Not for product improvement, not for marketing, not to train an AI system.
A named sub-processor list with locations. Every other company involved, and what country each operates in.
A retention and deletion schedule. What is kept, for how long, and what happens on cancellation.
Breach notification with a timeline. "Promptly" is not a timeline. A number of hours is.
Return or deletion at the end. Your retention obligations outlive the subscription; the agreement should say how you get everything out.
A stated legal characterisation of the relationship. Whether the vendor considers itself your agent, a service provider, or something else — because that determines which set of duties they are accepting.
What to do with it once you have it
Read it once. Save a copy outside the vendor's own system, because "it is in your account settings" is not helpful if you lose access to the account.
Then note the version. Agreements get updated, sub-processors change, and the copy a reviewer asks for is the one that was in force at the time of whatever they are asking about.
If a vendor has no such document at all, that is the finding. It does not necessarily mean the product is unsafe — but it does mean you have nothing to show for the reasonable steps you are required to have taken.
About Rivet
Rivet is a Canadian practice line built for therapists — a separate number for calls, texts and voicemail, with video sessions and clinical tools in the same place. Your data stays in Canada, and transcription runs on Rivet's own hardware rather than a third-party AI service.
One plan, $65 CAD a month, everything included. Fourteen-day trial, no card.