Compliance & regulations
What is PIPEDA, and does it apply to my business?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
PIPEDA — the Personal Information Protection and Electronic Documents Act — is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in commercial activity, and it applies to most private businesses across Canada, including sole proprietors and small firms. It does not apply where your activity is wholly within British Columbia, Alberta, or Quebec, whose own laws then govern. Federally regulated workplaces are always covered.
On this page
What is PIPEDA?
PIPEDA is the Personal Information Protection and Electronic Documents Act, Canada's federal law governing how private-sector organizations handle personal information during commercial activities. It sets the baseline rules for collecting, using, disclosing, retaining, and protecting personal information across the country, and it is overseen by the Office of the Privacy Commissioner of Canada (OPC).
Personal information under PIPEDA means information about an identifiable individual — names, contact details, ID numbers, financial and health information, online identifiers, and more. Commercial activity means any transaction, conduct, or regular course of business that is commercial in character, including selling, bartering, or leasing.
PIPEDA is built on ten fair information principles: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure, and retention; accuracy; safeguards; openness; individual access; and challenging compliance. These principles, rather than a rigid checklist, define what compliance looks like in practice.
Does PIPEDA apply to my business?
PIPEDA applies to most private-sector organizations that collect, use, or disclose personal information in the course of commercial activity anywhere in Canada — including sole proprietors, small businesses, charities that engage in commercial activity, and large enterprises. There is no revenue or headcount threshold: a one-person consultancy handling customer data is covered just as a national retailer is.
It always applies to federally regulated businesses — such as banks, airlines, telecommunications and broadcasting companies, and interprovincial transportation — including how they handle employee personal information.
PIPEDA also governs the interprovincial and international flow of personal information, so it reaches transactions and data transfers that move between provinces or in and out of Canada, even where a provincial law otherwise applies within a province.
- You sell products or services to customers in Canada and collect their information.
- You operate a website or app that gathers personal information from Canadian users.
- You are a federally regulated business (banking, telecom, transportation, broadcasting).
- You transfer personal information across provincial or national borders in the course of business.
When does PIPEDA NOT apply — and what replaces it?
PIPEDA does not apply where a province has enacted private-sector privacy legislation that the federal government has declared substantially similar, and the activity in question takes place wholly within that province. There, the provincial law governs intra-provincial commercial activity instead — though PIPEDA still applies to interprovincial and international data flows and to federally regulated workplaces in that province.
Quebec's Law 25 (which amended the province's Act respecting the protection of personal information in the private sector) is the most prescriptive of these, imposing requirements such as a designated person in charge of privacy, mandatory privacy impact assessments for certain projects, and strict consent and transfer rules. British Columbia and Alberta each have a Personal Information Protection Act (PIPA) covering their private sectors.
PIPEDA also does not cover personal information handled purely for personal, domestic, journalistic, artistic, or literary purposes. Public-sector personal information is governed by separate federal and provincial public-sector privacy statutes rather than by PIPEDA.
- British Columbia — Personal Information Protection Act (PIPA BC)
- Alberta — Personal Information Protection Act (PIPA Alberta)
- Quebec — Law 25 (amending the Act respecting the protection of personal information in the private sector)
- Health information in several provinces is also governed by sector laws such as Ontario's PHIPA
What does PIPEDA require you to do?
At a minimum, PIPEDA requires you to be accountable for the personal information you hold and to handle it in line with the ten principles. In practice that means a defined set of obligations you can build into normal operations rather than treat as a one-time project.
Mandatory breach reporting is a key obligation: if a breach of security safeguards creates a real risk of significant harm to an individual, you must report it to the OPC, notify affected individuals, and keep records of all breaches — even those you do not report.
- Appoint someone accountable for privacy compliance in your organization.
- Obtain meaningful consent and clearly identify why you collect personal information.
- Collect only what you need, and limit use, disclosure, and retention to those purposes.
- Protect personal information with safeguards appropriate to its sensitivity.
- Publish a clear, accessible privacy policy and respond to individual access requests.
- Report breaches that pose a real risk of significant harm, notify affected individuals, and log all breaches.
What happens if you do not comply?
Non-compliance can trigger OPC investigations following individual or commissioner-initiated complaints, leading to public findings. For certain breaches — such as failing to report a reportable breach or destroying records to evade an investigation — PIPEDA contains offence provisions that carry fines on conviction.
The harder costs are often commercial and reputational. Customers, enterprise buyers, healthcare organizations, and government procurement teams increasingly require evidence of sound privacy practices before they will do business. A mishandled breach or a public OPC finding can erode trust far beyond any statutory penalty.
Canada's privacy framework is also evolving: federal reform has been proposed that would raise the bar and introduce significant administrative monetary penalties, so building good practices now positions you well for stricter requirements ahead.
Frequently asked questions
Yes. PIPEDA has no minimum size or revenue threshold, so a sole proprietor or small business that collects personal information in the course of commercial activity is covered the same as a large enterprise. The practical obligations should be scaled to the sensitivity and volume of data you handle.
Only for federally regulated organizations such as banks, airlines, and telecoms — PIPEDA covers their employee personal information. For other private-sector businesses, employee information is generally governed by provincial law (or not specifically regulated) rather than by PIPEDA.
It can. The OPC takes the position that PIPEDA applies to organizations outside Canada that have a real and substantial connection to Canada, such as collecting personal information from people in Canada in the course of commercial activity. Foreign companies serving Canadian customers should not assume they are exempt.
Both protect personal information, but GDPR (the EU regime) is more prescriptive, with formal roles, lawful bases, data protection impact assessments, and large fines. PIPEDA is principles-based and consent-centred. An organization serving both markets typically aligns to the stricter standard to cover both.
It is provincial private-sector privacy legislation that the federal government has formally recognized as providing protection comparable to PIPEDA — currently British Columbia's and Alberta's PIPA and Quebec's Law 25. Where one applies, it governs commercial activity that takes place wholly within that province instead of PIPEDA.
Keep exploring
All Compliance & regulationsDoes HIPAA apply to my software or business?
HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business.
ReadCompliance & regulationsDoes GDPR apply to my business if we're outside Europe?
The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do.
ReadPrivacy & security assessmentsPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadPrivacy breach & incident responseWhat should I do after a data breach?
The steps to take after a data breach: contain it, investigate scope, meet your legal notification obligations (PIPEDA, GDPR, HIPAA), remediate, and document everything.
ReadCompliance & regulationsWhat is a HIPAA security risk assessment, and do you need one?
What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
Read