PIPEDA is unusual among privacy laws: its operative requirements live in a schedule, the ten fair information principles adopted from the CSA Model Code for the Protection of Personal Information. Everything the Office of the Privacy Commissioner investigates traces back to one of these ten, filtered through section 5(3)‘s overriding test: would a reasonable person consider the purpose appropriate in the circumstances?
| Regulation | PIPEDA (S.C. 2000, c. 5), Schedule 1 |
|---|---|
| Max penalty | CAD 100,000 per offence (specific violations); Federal Court damages |
| Enforcing authority | Office of the Privacy Commissioner of Canada |
| Official text | laws-lois.justice.gc.ca P-8.6 |
The ten principles, practically
- Accountability. Someone is designated responsible (a privacy officer), policies exist, and contractual protections follow data to service providers. The OPC starts most investigations here.
- Identifying Purposes. Say why you collect, at or before collection. New purposes need new consent.
- Consent. Knowledge and consent for collection, use, and disclosure, with the form (express or implied) calibrated to sensitivity and expectations. The OPC’s meaningful-consent guidelines require key elements be front and center: what, with whom, why, and residual risks.
- Limiting Collection. Only what the identified purposes need, by fair and lawful means.
- Limiting Use, Disclosure, and Retention. No purpose creep; destroy or anonymize when no longer required.
- Accuracy. As accurate and current as the purposes require, particularly where decisions about the person follow.
- Safeguards. Security proportionate to sensitivity: physical, organizational, technical. The principle behind most breach findings.
- Openness. A readily available, comprehensible privacy policy that matches reality.
- Individual Access. On request: what you hold, how it is used, who it went to, with correction rights. Respond within 30 days.
- Challenging Compliance. A complaint channel to your accountable person, and cooperation with the OPC.
Enforcement and where it bites
The OPC investigates complaints and self-initiates; outcomes are findings, compliance agreements, and Federal Court applications (the court can order remedies and damages). Named findings against Facebook (the Cambridge Analytica investigation, upheld by the Federal Court of Appeal in 2024), Home Depot (sharing purchase data with Meta without adequate consent, 2023), and the joint Clearview AI and TikTok investigations with provincial counterparts show the pattern: consent quality and transparency, not paperwork, decide cases. The 23andMe joint investigation with the UK ICO (2025) marked cross-border coordination on breach security.
The direct fine ceiling, CAD 100,000, attaches to specific offences: knowing breach-report failures, missing breach records, obstruction, whistleblower retaliation. The larger financial exposure is litigation: OPC findings routinely seed class actions. And reform is pending: Bill C-27 would have replaced PIPEDA with the CPPA and penalties up to 5% of global revenue; it died on the order paper in January 2025, but successor legislation along the same lines is widely expected. Quebec businesses face the stricter Law 25 today. For the GDPR-facing view, see PIPEDA vs. GDPR, and check your site’s consent behavior with a free scan.