Regulatory Compliance
The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25

Why Canadian privacy feels complicated (and why it isn't, once you have the map)
Ask a founder, a hospital administrator, or a government program lead which privacy law applies to them, and you will often get the same answer: a shrug. Canada does not have one privacy statute. It has a federal law, a patchwork of provincial laws, a separate set of rules for health information, and — in Quebec — a modernized regime that increasingly sets the pace for the rest of the country.
The good news is that the landscape is more orderly than it looks. Most of the confusion comes from not knowing which law governs which activity. Once you can place your organization on the map — what kind of data you hold, where, about whom, and for what purpose — the obligations fall into a manageable shape.
This is a 2026 snapshot of that map: the three pillars most organizations encounter — PIPEDA, the provincial health acts (with PHIPA as the worked example), and Quebec's Law 25 — and how to reason about which ones apply to you.
PIPEDA: the federal baseline for commercial activity
The Personal Information Protection and Electronic Documents Act (PIPEDA) is the federal private-sector privacy law. It applies to organizations that collect, use, or disclose personal information in the course of commercial activity, and it is overseen by the Office of the Privacy Commissioner of Canada (OPC). For most businesses, it is the default starting point.
PIPEDA is built on ten fair-information principles — accountability, identifying purposes, consent, limiting collection, safeguards, openness, individual access, and so on. In practice, that means you need a named person accountable for privacy, a reason for every piece of data you collect, meaningful consent, reasonable security safeguards, and a way for people to see and correct their information.
Two points trip people up. First, PIPEDA can apply to data that crosses provincial or national borders even where a provincial law would otherwise govern a purely intra-provincial activity. Second, breach reporting has been mandatory since November 2018: a breach posing a real risk of significant harm must be reported to the OPC and to affected individuals, and you must keep records of all breaches.
- Applies to: commercial collection, use, and disclosure of personal information by private-sector organizations.
- Regulator: the Office of the Privacy Commissioner of Canada (OPC).
- Core obligations: accountability, meaningful consent, purpose limitation, reasonable safeguards, access and correction, and mandatory breach reporting where there is a real risk of significant harm.
- Watch for: cross-border data flows, and provinces with their own substantially similar laws (British Columbia, Alberta, and Quebec) that displace PIPEDA for activity within the province.
The provincial overlay: when a local law takes over
PIPEDA is a baseline, not a ceiling. Several provinces have enacted private-sector laws deemed substantially similar to PIPEDA — British Columbia and Alberta both have a Personal Information Protection Act, and Quebec has its own private-sector regime, now modernized by Law 25. Where one of these applies, it generally governs personal information handled within that province, while PIPEDA continues to reach interprovincial and international flows.
There is also a public-sector layer. Provincial freedom-of-information and privacy statutes — for example British Columbia's FOIPPA — govern how government bodies and many of their contractors handle personal information. If you sell to or operate within the public sector, you are usually looking at these laws rather than PIPEDA, and the data-residency and assessment expectations can be stricter.
The takeaway is not to memorize every statute, but to ask three questions: Is this commercial or public-sector activity? Does it stay inside one province or cross a border? Is health information involved? Those answers point you to the right law far faster than reading them all.
Health information: PHIPA and its provincial siblings
Health information sits in its own category. Most provinces have a dedicated health privacy statute that takes precedence over the general private-sector law when personal health information is in play. Ontario's Personal Health Information Protection Act (PHIPA) is the most widely cited example, and it is administered by the Information and Privacy Commissioner of Ontario (IPC).
These laws define a class of health information custodians — hospitals, clinics, pharmacies, practitioners — and impose duties around consent, the circle of care, safeguards, and breach notification that are tailored to clinical reality. Crucially, they also reach the vendors who handle that data. A software company that processes patient information on behalf of a custodian, as its agent or service provider, inherits real obligations even though it never sees a patient.
This is where many SaaS and AI companies get caught out. Selling a scheduling tool, an analytics dashboard, or an AI scribe into a hospital means the health privacy regime — not just PIPEDA — shapes your contracts, your assessments, and your architecture. If you are heading into healthcare, expect to demonstrate, not merely assert, that patient data is protected.
- Health privacy laws (PHIPA in Ontario, and equivalents elsewhere) generally override the general private-sector law for personal health information.
- They define custodians and bind the agents and service providers who process health data on a custodian's behalf.
- Breach notification and consent rules are tailored to the clinical context — including the concept of the circle of care.
- Vendors selling into healthcare are typically expected to complete privacy and security assessments before any data changes hands.
Quebec Law 25: the regime everyone else is watching
Quebec's Law 25 (formerly Bill 64), through a phased rollout from 2022 to 2024, has made Quebec's private-sector privacy law the most demanding in Canada — and the closest in spirit to Europe's GDPR. If your organization touches the data of Quebec residents, it deserves direct attention rather than being folded into your PIPEDA program.
Several requirements go beyond the federal baseline. Organizations must designate a person in charge of the protection of personal information. A privacy impact assessment is required in defined situations, including before personal information is communicated outside Quebec. There are transparency rules for profiling and automated decision-making, a right to data portability, and administrative monetary penalties that raise the cost of getting it wrong.
The strategic point: Law 25 is becoming a de facto national standard. Federal privacy reform has been on the legislative agenda for years, and organizations that build to the Quebec bar tend to find compliance with the rest of Canada — and with international expectations — far easier. Treating Quebec as the high-water mark is usually a better investment than treating it as an exception.
- Requires a designated privacy officer (the person in charge of the protection of personal information).
- Mandates a privacy impact assessment in defined cases, including before communicating personal information outside Quebec.
- Adds transparency obligations for profiling and automated decision-making, plus a data-portability right.
- Carries significant administrative monetary penalties — a real shift from the historically advisory federal posture.
How the pieces fit: a working decision path
You rarely face just one of these laws. A telehealth startup based in Ontario, serving patients in Quebec, with servers in the United States, can simultaneously engage PHIPA (health data), Law 25 (Quebec residents and a cross-border transfer), and PIPEDA (interprovincial flow). The job is not to pick one law — it is to identify all of them and design to the strictest applicable obligation.
A simple sequence keeps this tractable: start with what data you hold, then where the people are, then where the data goes.
- Is health information involved? If yes, a provincial health privacy law (such as PHIPA) likely governs and binds your vendors.
- Is the data of Quebec residents in scope? If yes, build to Law 25 — designate a person in charge, run a privacy impact assessment, and document cross-border transfers.
- Is the activity commercial and interprovincial or international? PIPEDA applies, and breach reporting to the OPC is mandatory where there is a real risk of significant harm.
- Is a public-sector body or its contractor involved? A provincial FOIP/FOIPPA-style law and stricter assessment expectations come into play.
- When in doubt, design to the highest bar that any in-scope law sets — it is cheaper than maintaining separate regimes.
What to do with this in 2026
Mapping the law is the easy half. The harder, more valuable work is operational: knowing where your data lives, who can touch it, what you promised people you would do with it, and whether your safeguards match that promise. Most enforcement and most lost deals trace back not to a misread statute but to a gap between policy and practice.
If you are unsure where you sit on this map — or you are about to sell into healthcare or government and need to prove it — the fastest path is a focused assessment of what applies and where the gaps are, rather than a generic policy template. Get the map right first; the controls follow from it.
Privacy Horizon works across 43+ jurisdictions and helps healthcare, public-sector, and startup organizations turn this landscape into a clear, defensible program — from determining which laws apply, through privacy impact assessments, to standing in for a privacy officer where you need one.
Related reading
- Does PIPEDA apply to my business
- Does GDPR apply outside europe