SaaS Sprawl and Shadow IT: How 61% of the Apps Your Employees Use Create Compliance and Security Risk Under PIPEDA
Every quarter, a Canadian SMB signs up for a new project management tool, a new document signing service, a new AI writing assistant. Nobody calls IT. Within a year, a 30-person company has dozens of active SaaS subscriptions — and the number nobody knows is how many their employees have added on their own.
That gap has a name: shadow IT. And a 2026 benchmark report from SaaS management platform Torii found that 61.3% of applications in the average organization now operate outside formal IT oversight.
For Canadian SMBs, this matters for two reasons that go beyond the general IT management headache: security liability and PIPEDA accountability — and both are getting harder to ignore.
The Numbers Are Bigger Than Most IT Teams Expect
According to the Torii 2026 SaaS Benchmark Annual Report, released in February 2026, the average enterprise now runs more than 830 applications — with only 15.5% formally sanctioned by IT. The other 61.3% are shadow IT: tools employees signed up for, integrations they connected, browser extensions they installed, AI tools they started using independently.
BetterCloud's 2026 State of SaaS report puts the number in smaller context: companies average 106 SaaS applications, with 44% carrying no IT approval. The average employee uses 10 to 14 SaaS tools daily. Companies now deploy an average of 27 AI-powered SaaS applications — and that count is rising.
For most Canadian SMBs, the internal picture is messier than either report captures, because small teams have no formal process for tracking what tools people sign up for. A sales rep connects an AI email assistant to their corporate Gmail. A marketer subscribes to an AI image generator. A project manager uses a free tier of a workflow tool and invites the whole team. Each action is individually reasonable. Collectively, they create an unmanaged portfolio that carries real risk.
AI Is the Fastest-Growing Source of Shadow IT
Canadian businesses are adopting AI rapidly. Statistics Canada's Q2 2026 Canadian Survey on Business Conditions found that 19.2% of Canadian businesses now use AI to produce goods or deliver services — triple the 6.1% recorded in Q2 2024. The most common applications are data analytics (36.6%), text analytics (34.5%), and virtual agents or chatbots (28.2%).
A significant share of that adoption is happening without IT's involvement. The Torii 2026 report found that in 2025, 26 of the top 50 shadow IT applications discovered in enterprise environments were pure-play AI tools — ChatGPT, Claude, Midjourney, Perplexity, Grammarly Business, and dozens of others. Employees are subscribing directly, using personal or corporate credit cards, and connecting these tools to work email accounts without understanding the data handling implications.
The sensitivity of what flows through these connections is often significant: drafting client proposals in an AI writing tool means uploading client context. Using an AI image tool for a product launch means uploading brand assets and strategy. Asking a general-purpose AI to summarize a contract means uploading the contract.
The Security Consequences
The Verizon 2026 Data Breach Investigations Report, analyzing more than 22,000 confirmed breaches, found that cloud misconfiguration is now responsible for 14% of all global breaches — up from 9% in 2024. It is now the single largest technical breach vector. Most of these misconfigurations are not sophisticated: a storage bucket set to public access, an OAuth permission granted too broadly, a service account with admin rights that nobody reviews.
Shadow SaaS applications are misconfiguration factories. Each new tool an employee connects to a work account is a potential misconfiguration: an overpermissioned OAuth grant, a shared folder set to "anyone with the link," an AI tool that retains user data for model training by default unless explicitly opted out.
The DBIR's most significant finding for organizations with SaaS sprawl concerns third parties. Breaches involving a third party — where an attacker compromises a vendor or service provider to reach the primary target — jumped 60% year-over-year, now accounting for 48% of all confirmed breaches. When the "third party" is an unauthorized SaaS tool your employees connected to sensitive corporate data, the attack surface is difficult to defend because you do not know it exists.
The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025–2026 identifies supply chain and third-party compromise as a growing vector for Canadian organizations, with threat actors increasingly targeting smaller vendors and service providers to reach their real targets. An employee's unauthorized SaaS subscription is, from a security architecture standpoint, an unvetted vendor relationship with access to corporate data.
The PIPEDA Accountability Problem
This is where the Canadian-specific risk sharpens. PIPEDA's Accountability Principle — Principle 1 in Schedule 1 — states that organizations are responsible for personal information in their possession or under their control, including information that has been transferred to a third party for processing. Your organization remains accountable for what those third parties do with the data.
The Office of the Privacy Commissioner of Canada's guidance on accountability is explicit: before transferring personal information to a service provider, you must use contractual or other means to provide a comparable level of protection. An employee who signs up for a SaaS tool and uploads customer records — without any contractual relationship, data processing agreement, or security review — creates a PIPEDA accountability gap on behalf of your organization, regardless of whether IT was involved.
That gap becomes a liability the moment the tool has a breach. Your organization is required to assess whether the breach poses a real risk of significant harm to affected individuals, and if so, notify both the OPC and affected individuals — even if the breach happened at a vendor you did not formally authorize.
The incoming Bill C-36 (Protecting Privacy and Consumer Data Act), tabled in June 2026 and currently before Parliament, would formalize this further: organizations would be required to maintain documented privacy management programs including inventories of all service providers handling personal information. An unauthorized SaaS tool would be an unmanaged vendor relationship — and potentially an undisclosed privacy violation once the legislation comes into force.
Data Sovereignty Adds Another Layer
The CIRA 2025 Cybersecurity Survey found that 69% of Canadian organizations now cite data sovereignty as the most important sourcing factor when selecting technology vendors — up from 60% in 2024. And 56% are specifically reconsidering U.S. vendors in light of cross-border trade and political uncertainty.
Most shadow SaaS applications, particularly AI tools, run on U.S. infrastructure and are subject to U.S. legal process including national security orders that do not require notification to Canadian data subjects. An employee uploading customer information to an AI tool they found and subscribed to independently is almost certainly routing that data through U.S. data centers — with no review, no contractual protection, and no way for your organization to audit what happened to it.
For organizations that have made a deliberate decision about data residency — choosing Canadian-hosted tools or verifying in-country data processing for sensitive workloads — shadow SaaS is a direct circumvention of that decision, made by employees who are simply trying to get their work done faster.
What Canadian SMBs Can Do: A Practical Approach
Getting SaaS sprawl under control does not require a full IT audit or a specialized tool budget. A four-step approach addresses the most significant risks without disrupting how people work:
Step 1: Discover What Is Actually Running
Microsoft 365 Business Premium subscribers have access to Microsoft Defender for Cloud Apps, which analyses firewall and proxy logs and cloud API connections to surface SaaS applications in use — including ones IT did not know about. The tool provides a risk score for each discovered application based on its security configuration, regulatory compliance record, and data handling practices.
If you are not on M365 Business Premium, tools like Torii, Zylo, and Nudge Security perform discovery through SSO integration or network traffic analysis, typically returning a complete picture within 24 to 72 hours of activation. The Microsoft Defender for Cloud Apps SaaS Security Posture Management module also continuously monitors the configuration of your approved SaaS apps for drift from security baselines.
Step 2: Tier Your Applications
Not every SaaS tool requires the same scrutiny. A three-tier model is practical for most Canadian SMBs:
| Tier | Criteria | Required action |
|---|---|---|
| **Tier 1 — Critical** | Handles customer PII, financial data, or regulated information | Formal contract, data processing agreement, security review, SSO required |
| **Tier 2 — Standard** | Work productivity tools; no sensitive data in normal use | Approved list, SSO preferred, annual review |
| **Tier 3 — Unmanaged** | Personal tools, AI tools with no approved data handling policy | Block or require migration to an approved alternative |
The PIPEDA accountability requirement applies to any vendor holding personal information — which means every Tier 1 tool needs a contract, regardless of how the relationship started.
Step 3: Implement SSO as the Enforcement Point
Single Sign-On through Microsoft Entra ID or a comparable identity provider turns your identity system into a practical control. When employees authenticate through SSO to access approved tools, you gain visibility into active usage and the ability to enforce access policies — multi-factor authentication, device compliance, conditional access — consistently across your approved portfolio.
Any application that employees use outside SSO is, by definition, unmanaged. Making SSO the norm for approved applications makes shadow IT identifiable: if it is not in Entra ID, it is not sanctioned. When an employee's account is disabled at offboarding, SSO-connected apps are immediately revoked. Non-SSO apps are not.
Step 4: Build a SaaS Offboarding Workflow
Shadow IT and SaaS sprawl create their most serious security exposures during employee offboarding. A departing employee with active accounts at a dozen unmanaged SaaS tools — including tools IT never knew about — leaves standing access to corporate data at each of those services. The CIRA 2025 Cybersecurity Survey found that 24% of Canadian organizations experienced ransomware attacks in the past year; unauthorized SaaS accounts from former employees are a common initial access vector in these incidents.
A practical offboarding workflow: revoke all SSO-connected apps through the identity provider on the day of departure, review the departing employee's Entra ID access log for any non-SSO applications accessed in the last 90 days, and include a software-access declaration as part of HR offboarding paperwork.
A Consolidated Checklist
| Task | Priority | Tools |
|---|---|---|
| Run SaaS discovery scan | Do this first | Microsoft Defender for Cloud Apps, Torii, Nudge Security |
| Tier all discovered applications | High | Internal review using the three-tier model |
| Sign data processing agreements with all Tier 1 vendors | High — PIPEDA requires this | OPC contract template resources |
| Enable SSO for all Tier 1 and Tier 2 applications | High | Microsoft Entra ID |
| Build and publish an approved software list | Medium | Internal policy document |
| Add SaaS offboarding step to HR process | Medium | HR + IT workflow |
| Schedule quarterly SaaS portfolio reviews | Ongoing | SaaS management platform |
The investment in getting this under control is modest relative to the exposure it eliminates. A SaaS discovery scan takes hours. A data processing agreement template takes a day. An SSO rollout for 20 to 50 users takes a week. A ransomware incident from an unmanaged credential takes months and, according to the IBM 2026 Cost of a Data Breach Report, costs Canadian organizations an average of CA$7.11 million.
Sources
- Torii. *2026 SaaS Benchmark Annual Report: AI Isn't Consolidating SaaS — It's Expanding Shadow IT.* toriihq.com (February 2026)
- BetterCloud. *The 2026 State of SaaS Report.* bettercloud.com
- Statistics Canada. *Analysis on artificial intelligence use by businesses in Canada, second quarter of 2026.* statcan.gc.ca
- Verizon. *2026 Data Breach Investigations Report.* verizon.com
- Canadian Centre for Cyber Security. *National Cyber Threat Assessment 2025–2026.* cyber.gc.ca
- CIRA. *2025 CIRA Cybersecurity Survey.* cira.ca
- Office of the Privacy Commissioner of Canada. *PIPEDA Accountability Principle.* priv.gc.ca
- DLA Piper. *Canada Tables Bill C-36: The Protecting Privacy and Consumer Data Act.* June 2026. dlapiper.com
- Microsoft. *SaaS Security Posture Management in Microsoft Defender for Cloud Apps.* learn.microsoft.com
- IBM. *Cost of a Data Breach Report 2026.* ibm.com
Cloud Forces helps Canadian SMBs discover, tier, and govern their SaaS portfolio — from initial discovery using Microsoft Defender for Cloud Apps to SSO enforcement through Microsoft Entra ID, vendor data processing agreement review, and PIPEDA compliance assessment. Explore our Cybersecurity services or contact us to start with a SaaS discovery scan of your current environment.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation