Canada Canada

OPC Enforcement: How Canada's Privacy Regulator Works

The OPC's enforcement toolkit under PIPEDA: investigations, compliance agreements, Federal Court, and the Facebook and Clearview findings.

Regulation

PIPEDA; Privacy Act (public sector)

Max Penalty

CAD 100,000 per offence (PIPEDA offences); Federal Court damages

Enforcing Authority

Office of the Privacy Commissioner of Canada (OPC)

Official Source

www.priv.gc.ca

Executive Summary

  • The OPC is an ombudsman-model regulator: it investigates complaints and self-initiates, publishes findings, negotiates compliance agreements, and applies to the Federal Court, but cannot directly fine under PIPEDA.
  • Its landmark findings include Facebook/Cambridge Analytica (upheld by the Federal Court of Appeal in 2024), Home Depot's disclosure of purchase data to Meta (2023), Clearview AI's biometric scraping (2021), and the 23andMe breach (2025, jointly with the UK ICO).
  • The real financial consequences of OPC findings are downstream: remediation orders, reputational damage, and class actions that use findings as a litigation roadmap.
  • The OPC coordinates joint investigations with Quebec, Alberta, and BC counterparts, so one incident routinely triggers a multi-regulator response.
  • Offence prosecutions (breach-reporting failures, obstruction) carry fines up to CAD 100,000 per offence.

Canada’s federal privacy regulator does not write big cheques; it writes findings, and the findings do the damage. The Office of the Privacy Commissioner operates on an ombudsman model under PIPEDA: investigate, recommend, publish, and escalate to the Federal Court when organizations refuse. Companies that read “no direct fines” as “no risk” misunderstand how the last decade of Canadian privacy enforcement actually played out.

AuthorityOffice of the Privacy Commissioner of Canada
Direct finesNone under PIPEDA (offences to CAD 100,000 via prosecution)
Escalation pathCompliance agreements; Federal Court applications
Decisions databasepriv.gc.ca actions and decisions

The cases that define the OPC’s posture

Facebook (2019 finding; FCA 2024). The Cambridge Analytica investigation found meaningless consent for app-based disclosure of friends’ data. Facebook contested; the Federal Court of Appeal sided with the OPC in 2024, holding Facebook breached PIPEDA’s consent and safeguard duties, and a settlement with ongoing obligations followed. The lesson: findings are enforceable, just slowly.

Home Depot (2023). Sharing e-receipt email addresses and purchase data with Meta for ad measurement, relying on implied consent, failed: customers would not reasonably expect it, and the disclosure was invisible at collection. The finding reset Canadian expectations for retail data sharing with ad platforms.

Clearview AI (2021, joint). Scraping billions of face images was mass surveillance without consent for an inappropriate purpose; Clearview left the Canadian market and provincial orders followed. The companion RCMP finding put users of unlawful databases on notice too.

23andMe (2025, joint with the UK ICO). The credential-stuffing breach investigation found inadequate authentication safeguards; the ICO fined GBP 2.31 million on its side, while the OPC issued findings and recommendations, a clean illustration of the penalty gap between regimes.

What enforcement costs when there is no fine

Remediation programs (consent redesign, deletion, monitoring), compliance agreements with reporting duties, and above all litigation: Canadian class-action counsel treat OPC findings as pre-built liability roadmaps. Add the multi-regulator reality: joint investigations pull in Quebec’s CAI, which can fine up to CAD 25 million or 4% of turnover under Law 25, and the coming PIPEDA successor is expected to add federal penalties in the same range (Bill C-27’s CPPA proposed 5% of global revenue).

The defensible position is the one the OPC’s findings keep describing: consent people would recognize, disclosures that match reality, and safeguards proportionate to sensitivity, verifiable on your own site with a free scan. The baseline duties are in the PIPEDA principles guide.

Frequently Asked Questions

Can the OPC fine my company?

Not directly under PIPEDA. It publishes findings, negotiates binding compliance agreements, and can apply to the Federal Court, which can order damages and corrective measures. Specific offences (knowing breach-report failures, obstruction) are prosecuted with fines up to CAD 100,000. Quebec's CAI, by contrast, can levy penalties to CAD 25 million or 4% of turnover.

How does an OPC investigation start?

By individual complaint, or Commissioner-initiated when an issue appears systemic (data scraping, major breaches, high-profile media reports). The OPC gathers representations, can compel evidence, and issues a report of findings with recommendations, increasingly paired with a compliance agreement.

What was the Facebook case outcome?

The OPC found Facebook failed to obtain valid consent for disclosures to third-party apps in the Cambridge Analytica ecosystem. Facebook refused the findings; the OPC went to Federal Court; the Federal Court of Appeal ruled against Facebook in 2024, and a consent-and-monitoring settlement followed in 2025.

What should we do when the OPC contacts us?

Engage early and factually. Ombudsman-model regulators reward cooperation: negotiated compliance agreements close matters without court. Stonewalling produced the decade-long Facebook litigation. Preserve records, map the data flows in question, and bring remediation proposals to the first substantive response.

Do provincial regulators join OPC investigations?

Routinely. Clearview AI, TikTok, and 23andMe were joint investigations with the Quebec CAI, Alberta OIPC, and BC OIPC (23andMe with the UK ICO). Joint findings mean parallel enforcement, including Quebec's monetary penalties, from a single set of facts.

Regulatory Crosswalk

Quebec Law 25Alberta/BC PIPAsGDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.