What the OPC published
The guidance is a due-diligence checklist for any organization under PIPEDA that hands personal information to someone else: a hosting company, an analytics tool, an AI model provider. Its starting point is PIPEDA Principle 4.1.3: an organization remains responsible for personal information it transfers for processing, and must ensure comparable protection while it is there. From that the OPC derives best practices to apply before signing anything: know what personal information is involved and whether any of it is sensitive (health data is on the list); map the data flows and where the data is stored; confirm each purpose the provider will use the data for, in particular whether it intends to train an algorithm with it; confirm roles and responsibilities; assess out-of-country transfers; identify the source of a provider's training data; verify security and breach handling; weigh the risk of depending on a single provider, or of that provider disappearing; and confirm retention and what happens when the relationship ends.
The Commissioner's news release adds a sentence we agree with: "investing in privacy protection can be a competitive advantage."
Why users should care
Nothing on the checklist is exotic. What is unusual is that it puts the second-order question first. Most people evaluating a health app ask what it collects. The OPC asks who else touches it, under what terms, and for how long. A wellness app that stores almost nothing itself but forwards every entry to an analytics platform with its own retention rules has answered the first question well and the second not at all.
Users cannot audit a company's service-provider assessments. What they can read is the privacy policy. So a reasonable test of any health app is whether its policy answers the OPC's questions in public, in plain language, by name.
Reading Linnea's policy against the checklist
We build Linnea, a personal health record and score app for iPhone. Its privacy policy (version 1.5, effective 16 September 2026) was written before this guidance existed, which makes this a fair test. Here is how it reads, section by section.
What information is involved. Section 1 lists the categories the app handles. The most sensitive category is handled by reduction rather than by promise: Linnea reads Apple Health on the device and produces daily aggregates such as sleep totals, steps and workout minutes. Raw Apple Health samples never leave the device, and the service rejects payloads shaped like raw samples. All scoring math runs on the device too. Diagnostics follow the same idea: a central scrubber removes health fields and contact details before anything is transmitted, and analytics can be turned off in the app. The least data that reaches any provider is the data the app never collected.
Data flows and location. Section 4 names each processor and the job it does: hosting, requested AI features, subscription processing, sign-in, scrubbed diagnostics. Section 5 states that account data is stored in the United States and can therefore be processed under United States law, that database rows sit behind default-deny row-level access controls, and that the local device cache is encrypted. We would rather say the location plainly than let a reader assume otherwise.
Purposes, including training. Section 3: our commercial API arrangements do not permit the AI providers to train their general models on Linnea API data by default. They act as processors on our instructions and are not permitted to use the information for their own purposes. Their security and abuse-monitoring logs may be retained for up to 30 days under their standard API terms — a limit we disclose rather than round down to zero.
Comparable protection. The policy has a paragraph titled "Equal protection". It commits that we share personal information with an AI provider only under written commercial terms that bind the provider to confidentiality, to appropriate technical and organizational security measures, to processing the data solely to return the result of your request, and to protections materially equivalent to those in the policy itself. That is Principle 4.1.3, restated as one paragraph a user can read.
Consent at the user level. The guidance is about organizational diligence. Linnea adds a control the guidance does not ask for: "We ask before we send." Before the first AI request, the app explains in plain language what will be sent and which provider receives it, and nothing goes out until you agree. Withdraw that permission and the AI features stop sending, while logging, the daily score, trends, reminders and export keep working. Someone who wants no third party involved can decline and lose nothing else.
Retention and the end of the relationship. Section 6: data-export files are deleted after seven days and each download link expires after one hour; AI artifacts that are no longer referenced are purged after 90 days; account deletion has a 24-hour cancellation window, after which the account identity and associated application rows are deleted. The guidance's concern about depending on one provider has a user-side answer as well: Linnea exports everything as JSON, whenever you want.
What we do not claim
We do not describe any of this as compliance. The guidance is open for comment, and compliance is a regulator's judgment, not a marketing line. The policy itself says: "No Internet service can promise absolute security; Linnea limits access and data fields instead of making that promise." Service-provider diligence is the same idea applied one layer out: limit what leaves, name where it goes, bind how it is handled, and write down how long it stays. The policy carries a version number and an effective date, and it states that material changes are dated and shown in the app before they take effect where notice is required.
Five questions for any health app
Applied as a user, the guidance becomes five questions any health app's privacy policy should answer without hedging. Which companies receive my data, by name? In which country is it stored? Can any of them use it to train models, or for their own purposes? Am I asked before an AI feature sends anything? How long does each copy live, including after I leave? A policy that answers all five is doing the assessment in public. One that does not is asking for trust without showing its work.
Read the Linnea privacy policy in full — or tell us which of the five questions we should answer better.
Linnea provides organizational and informational tools only; it does not provide medical advice, diagnosis, or treatment. Always consult a qualified health professional for medical decisions. PIPEDA is the Personal Information Protection and Electronic Documents Act (Canada); the guidance discussed here is an OPC document open for public comment and this article is not legal advice. Apple and Apple Health are trademarks of Apple Inc., referenced for identification only; Arctura Technologies Inc. is not affiliated with or endorsed by Apple or by the Office of the Privacy Commissioner of Canada.
Sources
- Office of the Privacy Commissioner of Canada, news release, 10 September 2026 — "Privacy Commissioner of Canada releases guidance for businesses working with third-party service providers": priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260910/
- Office of the Privacy Commissioner of Canada — "Guidance on assessing third-party service providers" (consultation open until 4 December 2026): priv.gc.ca/en/privacy-topics/privacy-for-businesses/appropriate-handling-of-personal-information/gd_third-party_202609/
- Linnea Privacy Policy, version 1.5 (16 September 2026): arcturatech.com/linnea/privacy.html
- Linnea: Health Companion on the App Store: apps.apple.com/app/id6765480037