Global Privacy Law Canada

PIPEDA Overview: Canada's Federal Private-Sector Privacy Law

How PIPEDA works: the ten fair information principles, valid consent, breach reporting with CAD $100,000 offenses, OPC enforcement, provincial substitutes, and Quebec's stricter Law 25.

Regulation

Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, fully in force since January 1, 2004; mandatory breach reporting since November 1, 2018

Max Penalty

Fines up to CAD $100,000 per offense for knowing breach-reporting and record-keeping violations and whistleblower retaliation; Federal Court damages otherwise; Quebec's Law 25 reaches CAD $25 million or 4% of worldwide turnover

Enforcing Authority

Office of the Privacy Commissioner of Canada (OPC); prosecutions for offenses through the Attorney General; Federal Court for hearings and damages

Official Source

www.priv.gc.ca

Executive Summary

  • PIPEDA governs collection, use, and disclosure of personal information in the course of commercial activity across Canada, built on ten fair information principles from the CSA Model Code.
  • Consent is the backbone: meaningful, informed consent for identified purposes, express for sensitive information, with the OPC's guidelines defining what valid consent requires.
  • Breach of security safeguards rules since 2018 require reporting to the OPC and notifying individuals where there is a real risk of significant harm, plus mandatory breach record-keeping; knowing violations carry fines to CAD $100,000.
  • Alberta, BC, and Quebec run substantially similar provincial laws that displace PIPEDA intra-provincially; Quebec's Law 25 is now materially stricter, with penalties to CAD $25 million or 4% of turnover.
  • The EU maintains (conditionally reaffirmed in 2024) adequacy for PIPEDA-covered transfers; federal reform (the former Bill C-27) died in Parliament in 2025, leaving modernization pending.

PIPEDA is aging gracefully into a two-tier reality. Its principles-based core, consent, accountability, safeguards, access, remains a workable national floor, and OPC findings keep it current in application if not in penalty power. But the gravitational center of Canadian privacy has shifted to Quebec, where Law 25’s turnover-scaled fines and GDPR-grade obligations now set the ceiling a national program must actually clear, while federal reform waits for a new legislative vehicle. The strategic read for businesses is straightforward: treat PIPEDA compliance as necessary but not sufficient, build once to Quebec’s standard, keep the breach register and consent records that both regimes demand, and recognize that in Canada the cheapest compliance failure to prevent remains the same one the OPC cites most: promising purposes in a policy that the organization’s actual data flows quietly outgrew.

In forceFully since January 1, 2004; breach rules since November 1, 2018
ModelTen CSA fair information principles; consent-based, principles-based
RegulatorOPC (ombuds-style; findings, compliance agreements, Federal Court)
PenaltiesCAD $100,000 offenses (breach duties); Quebec reaches CAD $25M / 4%
EU adequacyMaintained in the 2024 review, reform encouraged
GuidanceOPC PIPEDA hub

Going deeper

Work the principles. The ten principles guide turns Schedule 1 into an operational checklist.

Ring-fence Quebec. Law 25’s requirements and Quebec PIAs exceed PIPEDA on nearly every axis.

Compare regimes. PIPEDA vs GDPR maps the gaps for companies running both.

Track reform. Bill C-27 readiness covers the shape any revived federal modernization is likely to take.

Consent starts at your website’s first pixel: see what fires before permission with a free scan.

Frequently Asked Questions

Who and what does PIPEDA cover, and where do provincial laws take over?

PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity, any transaction of a commercial character, across Canada, plus employee information of federally regulated works and undertakings (banks, airlines, telecoms, interprovincial transport). Personal information means information about an identifiable individual, read broadly. The federal-provincial architecture matters operationally: where a province enacts legislation deemed substantially similar, PIPEDA yields for intra-provincial activity, and three provinces qualify with general laws, Alberta's PIPA, British Columbia's PIPA, and Quebec's private-sector act (now transformed by Law 25), plus health-information laws in several provinces for custodians. PIPEDA still governs federally regulated employers everywhere, interprovincial and international flows, and commercial activity in the other provinces and territories. What escapes: purely non-commercial activity, journalistic and personal uses, most employee data of provincially regulated employers outside the three PIPA provinces (a genuine gap), and public-sector bodies (covered by the federal Privacy Act and provincial equivalents). For a national business the practical stack is PIPEDA as the floor, Alberta/BC PIPAs for those provinces' intra-provincial processing and employees, Quebec's stricter regime ring-fenced for Quebec, and CASL running separately for electronic marketing, one program built to Quebec's ceiling usually satisfies the rest.

What do the ten principles require in practice?

Schedule 1 embeds the CSA Model Code's ten principles as binding obligations. Accountability: designate a privacy officer, remain responsible for information transferred to third parties for processing (contractual protections required, the OPC's transfer position treats processing transfers as a 'use' requiring transparency rather than fresh consent). Identifying purposes: articulate why information is collected, at or before collection. Consent: the load-bearing principle, detailed below. Limiting collection: only what the identified purposes need, by fair and lawful means. Limiting use, disclosure, and retention: no repurposing without fresh consent, retention only as long as necessary with documented schedules, and destruction or anonymization after. Accuracy: as complete and current as purposes require. Safeguards: security proportionate to sensitivity, physical, organizational, technological, the principle behind every breach finding. Openness: readily available, understandable privacy policies naming the officer, the practices, and complaint routes. Individual access: on request, tell people what you hold, how it is used, and to whom disclosed, and correct it, within 30 days, with narrow exceptions (solicitor-client privilege, third-party information, prohibitive cost) that must be justified. Challenging compliance: a working complaint mechanism. The OPC investigates against these principles directly; its findings database is effectively PIPEDA's case law, and 'we had a policy' without operational evidence fails every principle it touches.

What counts as valid consent, and when must it be express?

Consent is valid only if it is reasonable to expect the individual understands the nature, purpose, and consequences of the collection, use, or disclosure, a statutory standard (s. 6.1) the OPC's Guidelines for Obtaining Meaningful Consent operationalize: emphasize four key elements (what is collected, with whom shared, for what purposes, and residual risks of significant harm); layer notices so the essentials surface up front; make consent granular per purpose where purposes are distinct; allow withdrawal (with explanation of consequences) at any time on reasonable notice; and design for the audience, including children (the OPC treats meaningful consent from young children as generally unobtainable, expecting parental consent under 13). Form follows sensitivity and expectations: express consent for sensitive information (health, financial, biometric, precise location as context makes sensitive) and for uses outside the individual's reasonable expectations; implied consent suffices where the purpose is obvious and expected in the transaction. The 'appropriate purposes' override (s. 5(3)) sits above consent: even with consent, purposes must be ones a reasonable person would consider appropriate in the circumstances, the provision the OPC used against Tim Hortons' continuous location tracking (2022) and the Clearview AI scraping joint investigation (2021), where consent was neither sought nor could have cured inappropriateness. Exceptions to consent exist (legal requirements, investigations, publicly available information as narrowly regulated, business-transaction due diligence, and the 2015-added business-contact and employment-relationship provisions), each with conditions; the pattern in OPC findings is that organizations stretch implied consent and the exceptions further than the findings database supports.

How do the breach rules work, and what are the penalties?

Since November 1, 2018, three duties attach to a breach of security safeguards (loss, unauthorized access, or unauthorized disclosure resulting from a safeguards failure). Report: to the OPC, as soon as feasible, any breach creating a real risk of significant harm (RROSH), judged on sensitivity and probability of misuse; significant harm includes bodily harm, humiliation, reputational damage, financial loss, identity theft, and credit-record effects, a deliberately broad list. Notify: affected individuals, as soon as feasible, with enough information to understand the significance and mitigate, plus notification to other organizations (payment processors, credit bureaus) that can reduce the harm. Record: keep records of every breach of security safeguards, RROSH or not, for at least 24 months, producible to the OPC on demand, the duty organizations most often fail because sub-threshold incidents go unlogged. Penalties: knowingly failing to report, notify, or keep records, or retaliating against whistleblowers, is an offense with fines up to CAD $100,000 (per individual not notified, on the OPC's reading of summary-conviction exposure). PIPEDA otherwise lacks direct administrative fining power: the OPC investigates, issues findings and compliance agreements, and can take matters to Federal Court, where individuals can also seek damages (awards have been modest, though class actions after major breaches do the heavier financial work). Contrast Quebec: Law 25 carries administrative penalties to CAD $10 million or 2% and penal fines to CAD $25 million or 4% of worldwide turnover, with a similar confidentiality-incident regime, and its own register and reporting to the CAI, national incident-response plans must fork for Quebec.

Where is Canadian privacy law heading after C-27's death, and what should companies do now?

Bill C-27, the CPPA package that would have replaced PIPEDA's Part 1 with an administrative-penalty regime (up to CAD $10 million or 3% for violations, 5% or CAD $25 million for offenses), a tribunal, and the AIDA AI law, died on the Order Paper when Parliament was prorogued in January 2025 and was not revived in that form; federal modernization is again a matter of announced intention rather than pending text. What fills the space: the OPC's active enforcement posture (joint investigations with provincial counterparts on TikTok's children's-data practices in 2025, OpenAI, Aylo/Pornhub compliance agreement in 2025, the 23andMe joint findings with the UK ICO); Quebec's Law 25 operating as the country's de facto strictest standard since its September 2023 core and September 2024 portability provisions took full effect; and the EU's January 2024 adequacy review, which maintained Canada's adequacy for PIPEDA-covered transfers while explicitly encouraging reform, keeping modernization pressure alive. The prudent corporate posture: build to Quebec's requirements where you touch Quebec (privacy officer publicly named, PIAs including for out-of-province transfers, consent granularity, confidentiality-incident register, automated-decision disclosures, de-indexing rights); keep PIPEDA fundamentals audit-ready (consent records, breach register, retention schedules, access-request workflow within the 30 days); expect any revived federal reform to look like C-27's shape, penalties, a tribunal, refusal rights, and codified legitimate-interest-style exceptions, so investments in consent management, breach machinery, and assessments carry forward; and watch OPC guidance (biometrics, children, AI training data) as the near-term source of new obligations, since the Commissioner regulates through findings and guidelines faster than Parliament legislates.

Regulatory Crosswalk

Quebec Law 25Alberta and BC PIPAsGDPRCASL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.