Canada Canada

PIPEDA's 10 Fair Information Principles Explained

The ten fair information principles in PIPEDA Schedule 1, what each requires in practice, who enforces them, and the real penalty exposure.

Regulation

Personal Information Protection and Electronic Documents Act (PIPEDA), Schedule 1

Max Penalty

CAD 100,000 per offence for specific violations; Federal Court damages

Enforcing Authority

Office of the Privacy Commissioner of Canada (OPC)

Official Source

laws-lois.justice.gc.ca

Executive Summary

  • PIPEDA governs private-sector handling of personal information in commercial activity across Canada, except where provinces have substantially similar laws (Quebec, Alberta, BC for their spheres).
  • Its substance is Schedule 1: ten fair information principles drawn from the CSA Model Code, from Accountability through Challenging Compliance.
  • Consent is the backbone (Principle 3), but PIPEDA's meaningful-consent guidelines and the appropriateness test in section 5(3) do the real work.
  • Enforcement runs through OPC investigations, compliance agreements, and Federal Court applications; offences such as obstructing an investigation or breach-reporting failures carry fines up to CAD 100,000.
  • Breach reporting has been mandatory since 1 November 2018: report to the OPC and notify individuals when a breach creates a real risk of significant harm.

PIPEDA is unusual among privacy laws: its operative requirements live in a schedule, the ten fair information principles adopted from the CSA Model Code for the Protection of Personal Information. Everything the Office of the Privacy Commissioner investigates traces back to one of these ten, filtered through section 5(3)‘s overriding test: would a reasonable person consider the purpose appropriate in the circumstances?

RegulationPIPEDA (S.C. 2000, c. 5), Schedule 1
Max penaltyCAD 100,000 per offence (specific violations); Federal Court damages
Enforcing authorityOffice of the Privacy Commissioner of Canada
Official textlaws-lois.justice.gc.ca P-8.6

The ten principles, practically

  1. Accountability. Someone is designated responsible (a privacy officer), policies exist, and contractual protections follow data to service providers. The OPC starts most investigations here.
  2. Identifying Purposes. Say why you collect, at or before collection. New purposes need new consent.
  3. Consent. Knowledge and consent for collection, use, and disclosure, with the form (express or implied) calibrated to sensitivity and expectations. The OPC’s meaningful-consent guidelines require key elements be front and center: what, with whom, why, and residual risks.
  4. Limiting Collection. Only what the identified purposes need, by fair and lawful means.
  5. Limiting Use, Disclosure, and Retention. No purpose creep; destroy or anonymize when no longer required.
  6. Accuracy. As accurate and current as the purposes require, particularly where decisions about the person follow.
  7. Safeguards. Security proportionate to sensitivity: physical, organizational, technical. The principle behind most breach findings.
  8. Openness. A readily available, comprehensible privacy policy that matches reality.
  9. Individual Access. On request: what you hold, how it is used, who it went to, with correction rights. Respond within 30 days.
  10. Challenging Compliance. A complaint channel to your accountable person, and cooperation with the OPC.

Enforcement and where it bites

The OPC investigates complaints and self-initiates; outcomes are findings, compliance agreements, and Federal Court applications (the court can order remedies and damages). Named findings against Facebook (the Cambridge Analytica investigation, upheld by the Federal Court of Appeal in 2024), Home Depot (sharing purchase data with Meta without adequate consent, 2023), and the joint Clearview AI and TikTok investigations with provincial counterparts show the pattern: consent quality and transparency, not paperwork, decide cases. The 23andMe joint investigation with the UK ICO (2025) marked cross-border coordination on breach security.

The direct fine ceiling, CAD 100,000, attaches to specific offences: knowing breach-report failures, missing breach records, obstruction, whistleblower retaliation. The larger financial exposure is litigation: OPC findings routinely seed class actions. And reform is pending: Bill C-27 would have replaced PIPEDA with the CPPA and penalties up to 5% of global revenue; it died on the order paper in January 2025, but successor legislation along the same lines is widely expected. Quebec businesses face the stricter Law 25 today. For the GDPR-facing view, see PIPEDA vs. GDPR, and check your site’s consent behavior with a free scan.

Frequently Asked Questions

Who has to comply with PIPEDA?

Private-sector organizations collecting, using, or disclosing personal information in the course of commercial activity in Canada, including foreign companies with a real and substantial connection to Canada. Quebec, Alberta, and BC organizations follow their provincial laws for intra-provincial matters, but PIPEDA still covers interprovincial and international flows and federal works.

What are the ten principles?

Accountability; Identifying Purposes; Consent; Limiting Collection; Limiting Use, Disclosure, and Retention; Accuracy; Safeguards; Openness; Individual Access; and Challenging Compliance. They come from the CSA Model Code and are legally binding through Schedule 1.

What penalties does PIPEDA carry?

Direct fines are narrow: up to CAD 100,000 per offence for knowingly violating breach-reporting duties, failing to retain breach records, obstructing an investigation, or retaliating against whistleblowers. Broader monetary exposure comes via Federal Court damages and, increasingly, class actions following OPC findings.

Is PIPEDA consent like GDPR consent?

Different architecture. PIPEDA makes consent the default requirement for nearly all collection, use, and disclosure, but allows implied consent for non-sensitive information in expected contexts. GDPR treats consent as one of six lawful bases. Both demand that consent be meaningful and withdrawable.

When must breaches be reported?

Since 1 November 2018: report to the OPC and notify affected individuals as soon as feasible when a breach of security safeguards creates a real risk of significant harm, and keep records of every breach for 24 months. Knowing failures are offences fined up to CAD 100,000.

Regulatory Crosswalk

GDPRQuebec Law 25Alberta/BC PIPAs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.