Who and what does PIPEDA cover, and where do provincial laws take over?
PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity, any transaction of a commercial character, across Canada, plus employee information of federally regulated works and undertakings (banks, airlines, telecoms, interprovincial transport). Personal information means information about an identifiable individual, read broadly. The federal-provincial architecture matters operationally: where a province enacts legislation deemed substantially similar, PIPEDA yields for intra-provincial activity, and three provinces qualify with general laws, Alberta's PIPA, British Columbia's PIPA, and Quebec's private-sector act (now transformed by Law 25), plus health-information laws in several provinces for custodians. PIPEDA still governs federally regulated employers everywhere, interprovincial and international flows, and commercial activity in the other provinces and territories. What escapes: purely non-commercial activity, journalistic and personal uses, most employee data of provincially regulated employers outside the three PIPA provinces (a genuine gap), and public-sector bodies (covered by the federal Privacy Act and provincial equivalents). For a national business the practical stack is PIPEDA as the floor, Alberta/BC PIPAs for those provinces' intra-provincial processing and employees, Quebec's stricter regime ring-fenced for Quebec, and CASL running separately for electronic marketing, one program built to Quebec's ceiling usually satisfies the rest.
What do the ten principles require in practice?
Schedule 1 embeds the CSA Model Code's ten principles as binding obligations. Accountability: designate a privacy officer, remain responsible for information transferred to third parties for processing (contractual protections required, the OPC's transfer position treats processing transfers as a 'use' requiring transparency rather than fresh consent). Identifying purposes: articulate why information is collected, at or before collection. Consent: the load-bearing principle, detailed below. Limiting collection: only what the identified purposes need, by fair and lawful means. Limiting use, disclosure, and retention: no repurposing without fresh consent, retention only as long as necessary with documented schedules, and destruction or anonymization after. Accuracy: as complete and current as purposes require. Safeguards: security proportionate to sensitivity, physical, organizational, technological, the principle behind every breach finding. Openness: readily available, understandable privacy policies naming the officer, the practices, and complaint routes. Individual access: on request, tell people what you hold, how it is used, and to whom disclosed, and correct it, within 30 days, with narrow exceptions (solicitor-client privilege, third-party information, prohibitive cost) that must be justified. Challenging compliance: a working complaint mechanism. The OPC investigates against these principles directly; its findings database is effectively PIPEDA's case law, and 'we had a policy' without operational evidence fails every principle it touches.
What counts as valid consent, and when must it be express?
Consent is valid only if it is reasonable to expect the individual understands the nature, purpose, and consequences of the collection, use, or disclosure, a statutory standard (s. 6.1) the OPC's Guidelines for Obtaining Meaningful Consent operationalize: emphasize four key elements (what is collected, with whom shared, for what purposes, and residual risks of significant harm); layer notices so the essentials surface up front; make consent granular per purpose where purposes are distinct; allow withdrawal (with explanation of consequences) at any time on reasonable notice; and design for the audience, including children (the OPC treats meaningful consent from young children as generally unobtainable, expecting parental consent under 13). Form follows sensitivity and expectations: express consent for sensitive information (health, financial, biometric, precise location as context makes sensitive) and for uses outside the individual's reasonable expectations; implied consent suffices where the purpose is obvious and expected in the transaction. The 'appropriate purposes' override (s. 5(3)) sits above consent: even with consent, purposes must be ones a reasonable person would consider appropriate in the circumstances, the provision the OPC used against Tim Hortons' continuous location tracking (2022) and the Clearview AI scraping joint investigation (2021), where consent was neither sought nor could have cured inappropriateness. Exceptions to consent exist (legal requirements, investigations, publicly available information as narrowly regulated, business-transaction due diligence, and the 2015-added business-contact and employment-relationship provisions), each with conditions; the pattern in OPC findings is that organizations stretch implied consent and the exceptions further than the findings database supports.
How do the breach rules work, and what are the penalties?
Since November 1, 2018, three duties attach to a breach of security safeguards (loss, unauthorized access, or unauthorized disclosure resulting from a safeguards failure). Report: to the OPC, as soon as feasible, any breach creating a real risk of significant harm (RROSH), judged on sensitivity and probability of misuse; significant harm includes bodily harm, humiliation, reputational damage, financial loss, identity theft, and credit-record effects, a deliberately broad list. Notify: affected individuals, as soon as feasible, with enough information to understand the significance and mitigate, plus notification to other organizations (payment processors, credit bureaus) that can reduce the harm. Record: keep records of every breach of security safeguards, RROSH or not, for at least 24 months, producible to the OPC on demand, the duty organizations most often fail because sub-threshold incidents go unlogged. Penalties: knowingly failing to report, notify, or keep records, or retaliating against whistleblowers, is an offense with fines up to CAD $100,000 (per individual not notified, on the OPC's reading of summary-conviction exposure). PIPEDA otherwise lacks direct administrative fining power: the OPC investigates, issues findings and compliance agreements, and can take matters to Federal Court, where individuals can also seek damages (awards have been modest, though class actions after major breaches do the heavier financial work). Contrast Quebec: Law 25 carries administrative penalties to CAD $10 million or 2% and penal fines to CAD $25 million or 4% of worldwide turnover, with a similar confidentiality-incident regime, and its own register and reporting to the CAI, national incident-response plans must fork for Quebec.
Where is Canadian privacy law heading after C-27's death, and what should companies do now?
Bill C-27, the CPPA package that would have replaced PIPEDA's Part 1 with an administrative-penalty regime (up to CAD $10 million or 3% for violations, 5% or CAD $25 million for offenses), a tribunal, and the AIDA AI law, died on the Order Paper when Parliament was prorogued in January 2025 and was not revived in that form; federal modernization is again a matter of announced intention rather than pending text. What fills the space: the OPC's active enforcement posture (joint investigations with provincial counterparts on TikTok's children's-data practices in 2025, OpenAI, Aylo/Pornhub compliance agreement in 2025, the 23andMe joint findings with the UK ICO); Quebec's Law 25 operating as the country's de facto strictest standard since its September 2023 core and September 2024 portability provisions took full effect; and the EU's January 2024 adequacy review, which maintained Canada's adequacy for PIPEDA-covered transfers while explicitly encouraging reform, keeping modernization pressure alive. The prudent corporate posture: build to Quebec's requirements where you touch Quebec (privacy officer publicly named, PIAs including for out-of-province transfers, consent granularity, confidentiality-incident register, automated-decision disclosures, de-indexing rights); keep PIPEDA fundamentals audit-ready (consent records, breach register, retention schedules, access-request workflow within the 30 days); expect any revived federal reform to look like C-27's shape, penalties, a tribunal, refusal rights, and codified legitimate-interest-style exceptions, so investments in consent management, breach machinery, and assessments carry forward; and watch OPC guidance (biometrics, children, AI training data) as the near-term source of new obligations, since the Commissioner regulates through findings and guidelines faster than Parliament legislates.