Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Canada’s Federal Privacy Law

PIPEDA Compliance for Canadian Businesses

The Personal Information Protection and Electronic Documents Act sets the ground rules for how private-sector organizations collect, use and disclose personal information in commercial activity. We help you meet every principle — and prove it to customers, partners and the Privacy Commissioner.

The Basics

What PIPEDA is and who it applies to

PIPEDA is Canada’s federal private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of commercial activity, to federally regulated businesses such as banks, airlines and telecoms, and to personal information that crosses provincial or national borders. It is overseen by the Office of the Privacy Commissioner of Canada (OPC).

Where a province has enacted a substantially similar law, that law takes over for activity inside the province: Quebec, Alberta and British Columbia for the private sector generally, and Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia for health information custodians. Most organizations with customers in more than one province therefore answer to PIPEDA and at least one provincial regime — such asPIPA orPHIPA — at the same time.

The Act is built on ten fair information principles set out in its Schedule 1. Understanding them is the fastest way to understand what compliance actually requires. Our plain-language explainer,Understanding PIPEDA, is a good place to start, andDoes PIPEDA apply to my business?answers the scope question directly.

Commercial Activity

Any organization that collects, uses or discloses personal information in the course of a commercial activity — selling, bartering or leasing, whether or not for profit.

Federally Regulated Businesses

Banks, airlines, telecommunications and other federal works and undertakings are covered in full, including their employees’ personal information.

Cross-Border & Inter-Provincial Data

Personal information that crosses a provincial or national border for commercial purposes falls under PIPEDA regardless of where the organization sits.

Substantially Similar Provincial Laws

Quebec, Alberta and BC (private sector), and Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia (health custodians) take over for activity inside the province.

Key Requirements

The 10 fair information principles

Business team working with customer data on laptops in an open office — personal information governed by PIPEDA’s fair information principles
  1. Accountability

    Designate someone responsible for compliance, and remain accountable for personal information you transfer to third parties for processing.

  2. Identifying purposes

    Identify why you are collecting personal information at or before the time of collection, and document it.

  3. Consent

    Obtain meaningful, knowing consent for collection, use and disclosure — express or implied depending on sensitivity and reasonable expectations.

  4. Limiting collection

    Collect only what is necessary for the identified purposes, by fair and lawful means.

  5. Limiting use, disclosure and retention

    Use or disclose personal information only for the purposes it was collected for, and keep it only as long as those purposes require.

  6. Accuracy

    Keep personal information as accurate, complete and up to date as the purposes require.

  7. Safeguards

    Protect personal information with security safeguards appropriate to its sensitivity — physical, organizational and technological.

  8. Openness

    Make your policies and practices readily available in an understandable form.

  9. Individual access

    On request, tell individuals what personal information you hold about them, how it is used and to whom it has been disclosed, and let them challenge its accuracy.

  10. Challenging compliance

    Provide a way for individuals to challenge your compliance with the principles, and investigate and act on every complaint.

Breach Rules

Mandatory breach reporting under PIPEDA

Three obligations apply to every organization under PIPEDA the moment a security safeguard fails — and the record-keeping one applies even when nobody needs to be told.

Report to the Privacy Commissioner

Since November 1, 2018, breaches of security safeguards that pose a real risk of significant harm to an individual must be reported to the Office of the Privacy Commissioner of Canada as soon as feasible.

Notify Affected Individuals

Individuals at real risk of significant harm must be notified directly, and other organizations or government bodies that can reduce the harm must be told as well.

Keep a 24-Month Breach Record

Every breach of security safeguards — not just the reportable ones — must be recorded and the record kept for 24 months and provided to the OPC on request.

For the full test and a walk-through of the record you need to keep, readPIPEDA breach notification and record-keeping— and if something has already happened,what to do after a data breach.

Our Services

Our PIPEDA compliance services

A complete approach to federal privacy compliance, from the first gap analysis to the privacy officer who keeps it running.

Privacy Gap Analysis

A detailed review of your data practices against the 10 fair information principles and the OPC’s guidance, producing a prioritized list of what to fix.

Policy Development

Privacy policies, public-facing notices, consent forms and internal procedures written for your business rather than adapted from a template.

Consent & Notice Design

Consent flows and purpose statements that are meaningful to real people — the standard the OPC actually applies — without stalling your sign-up or sales process.

Breach Response Planning

An incident plan with the real-risk-of-significant-harm test built in, the OPC report template ready, and the 24-month breach log in place before you need it.

Staff Training & Awareness

Role-based training so your team understands its obligations and handles personal information responsibly, with records to show for it.

Ongoing Privacy Office

A Virtual Privacy Officer who fills the accountability role, answers customer questionnaires and keeps the program current as the law tightens.

Most programs combinepolicy development,custom training, aPrivacy Impact Assessmentfor new products, and aVirtual Privacy Officer. For the fastest credible baseline, start withMinimum Viable Privacyor browse allcompliance services.

Why It Matters

Why PIPEDA compliance matters

Beyond legal necessity, privacy compliance is a cornerstone of digital trust. Failing to protect personal information leads to investigations, penalties, legal action and reputational damage — and passing the test earns business.

Avoid Penalties and Investigations

Knowingly failing to report or record a breach is an offence with fines of up to $100,000. OPC investigations, compliance agreements and Federal Court applications cost far more in time and reputation.

Win and Keep Customers

Privacy compliance is now a line item in procurement, a clause in enterprise contracts and a trust signal for consumers. A documented program answers the question before it is asked.

Be Ready for What’s Next

Quebec’s Law 25 has raised the provincial bar and federal reform remains on the agenda, so requirements are expected to tighten. A program built on the principles today adapts tomorrow.

How We Work

From data map to a sustained program in four steps

  1. Scope

    Map what personal information you hold, where it flows, which provinces and borders it crosses, and which laws therefore apply.

  2. Assess

    Measure your practices against the 10 principles and the breach rules, and rank the gaps by risk.

  3. Remediate

    Close the gaps in priority order — accountability, policies, consent, safeguards, retention, access workflow, breach plan — with your team doing the work and ours guiding it.

  4. Sustain

    Annual reviews, training refreshes and a privacy officer on call keep the program current as your business and the law change.

FAQ

PIPEDA compliance questions, answered

Short answers to what Canadian businesses ask us most.

PIPEDA applies if you collect, use or disclose personal information in the course of commercial activity, if you are a federally regulated business such as a bank, airline or telecom, or if personal information you handle crosses a provincial or national border. In Quebec, Alberta and British Columbia — and for health custodians in Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia — a substantially similar provincial law applies instead for activity inside the province, but PIPEDA still governs the cross-border part.

They are the heart of PIPEDA, set out in Schedule 1 of the Act: Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use, Disclosure and Retention, Accuracy, Safeguards, Openness, Individual Access, and Challenging Compliance. Every obligation in the law traces back to one of them, which is why a gap analysis organized principle by principle is the clearest way to see where you stand.

Since November 1, 2018, you must report a breach of security safeguards to the Office of the Privacy Commissioner of Canada as soon as feasible if it is reasonable to believe the breach creates a real risk of significant harm to an individual — considering the sensitivity of the information and the probability it will be misused. You must also notify the affected individuals and any organization that can reduce the harm, and record every breach, reportable or not, for 24 months.

Knowingly failing to report a breach to the Commissioner, to notify affected individuals or to keep the required breach records is an offence punishable by fines of up to $100,000. The Commissioner can also investigate complaints, publish findings, enter into compliance agreements and apply to the Federal Court, which can order changes to your practices and award damages. Requirements are widely expected to tighten as reform continues.

Yes. The Accountability principle requires you to designate one or more individuals responsible for your compliance with PIPEDA and to make their identity known on request. The role can be part-time or outsourced, but the person needs real authority and real knowledge of your information flows. Many small and mid-sized businesses fill it with a Virtual Privacy Officer rather than a full-time hire.

Generally yes. PIPEDA does not prohibit transfers outside Canada, but you remain accountable for the information while a third party processes it, must use contractual and other means to provide a comparable level of protection, and must be transparent with individuals that their information may be stored or processed abroad and subject to foreign law. Some provinces, sectors and public-sector customers add their own residency requirements, so check the contract.

The provincial laws are substantially similar to PIPEDA, so a program built on the fair information principles covers most of the ground. The differences are in the details: Quebec’s Law 25 adds stricter consent, privacy-impact-assessment and transparency requirements with significant penalties; Alberta and BC’s PIPAs add employee-information rules and, in Alberta, foreign-service-provider notice and breach reporting; and the health-sector laws add custodian-specific duties. We design one program that meets every regime you answer to.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

What do you need a quote for? (select all that apply)

We only use your details to respond to this request.