Skip to content

Canada (federal, private sector) · In force since 2001, with breach reporting duties added in 2018

Canada — Personal Information Protection and Electronic Documents Act (PIPEDA)

Canada's federal private-sector privacy law, built on ten fair information principles and a consent-centred model, with an ombudsman-style regulator and substantially similar provincial regimes in some provinces.

Regulator: Office of the Privacy Commissioner of CanadaLast reviewed August 2026

PIPEDA applies to personal information that private-sector organisations collect, use or disclose in the course of commercial activities. It also applies to employee information of federally regulated organisations such as banks, airlines and telecommunications providers.

It is principles-based. Schedule 1 sets out ten fair information principles that function as the operative obligations, moderated by an overarching reasonableness standard: an organisation may only handle personal information in ways a reasonable person would consider appropriate in the circumstances.

Where a province has enacted legislation deemed substantially similar — Quebec, British Columbia and Alberta for private-sector personal information — that provincial law applies to intra-provincial activity, with PIPEDA continuing to cover interprovincial and international flows.

Quebec's modernised regime in particular imposes stricter obligations than PIPEDA, including privacy impact assessment duties and transparency about automated decisions, so a Canada-wide programme should be designed to the higher provincial bar.

Who and what it applies to

Commercial activity
Collection, use or disclosure of personal information in the course of commercial activities by private-sector organisations.
Employee information
Covered for federally regulated works, undertakings and businesses; otherwise employee privacy is a provincial matter.
Provincial interaction
Substantially similar provincial laws displace PIPEDA for intra-provincial activity, while PIPEDA still governs cross-border and interprovincial flows.

Core principles

  • Accountability — a designated individual is responsible for compliance.
  • Identifying purposes — purposes must be identified at or before collection.
  • Consent — knowledge and consent are required, with limited exceptions.
  • Limiting collection — collect only what is necessary for the identified purposes.
  • Limiting use, disclosure and retention — use and keep only as needed, then destroy or anonymise.
  • Accuracy — keep information accurate, complete and up to date as needed.
  • Safeguards — protect information with security appropriate to its sensitivity.
  • Openness — make privacy policies and practices readily available.
  • Individual access — provide access and the ability to challenge accuracy.
  • Challenging compliance — provide a complaint process to the designated individual.

Individual rights

Access

Be told of the existence, use and disclosure of their personal information and be given access to it.

Correction

Challenge the accuracy and completeness of information and have it amended as appropriate.

Withdraw consent

Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.

Complain

Complain to the organisation and then to the Office of the Privacy Commissioner of Canada.

Organisational obligations

Meaningful consent

Highlight key elements — what is collected, with whom it is shared, the purposes, and the risk of harm — in a way people can actually understand.

Accountability for transfers

An organisation transferring personal information to a third party for processing remains accountable and must use contractual or other means to provide comparable protection.

Breach of security safeguards

Report breaches posing a real risk of significant harm to the Commissioner and notify affected individuals, and keep records of all breaches regardless of reportability.

Openness

Publish accessible information about policies, complaint routes and the identity of the accountable individual.

Retention

Retain information used for a decision about an individual long enough to allow access, then destroy, erase or anonymise it.

Cross-border considerations

  • PIPEDA treats a transfer for processing as a use, not a disclosure, provided the information is used only for the original purpose.
  • The transferring organisation remains accountable and must ensure a comparable level of protection through contractual or other means.
  • Individuals should be informed that their information may be processed in another country and may be accessible to foreign authorities under local law.
  • Quebec imposes an additional assessment obligation before transferring personal information outside the province.

Enforcement overview

  • The Office of the Privacy Commissioner of Canada investigates complaints, conducts audits and issues findings and recommendations; it operates in an ombudsman model rather than issuing fines directly under PIPEDA.
  • Matters can proceed to the Federal Court, which may order remedies including damages.
  • Offence provisions exist for obstructing an investigation and for failing to report or record breaches.
  • Provincial regulators enforce provincial regimes, and Quebec's regime provides for significantly stronger penalties.

Implementation checklist

  1. 1Designate an accountable individual and publish how to reach them.
  2. 2Identify and document purposes at or before collection, in plain language.
  3. 3Review consent design against the meaningful consent expectations, especially for sensitive information.
  4. 4Maintain a breach record for every incident, and a documented real-risk-of-significant-harm assessment.
  5. 5Assess whether provincial regimes apply and design to the strictest applicable requirement.
  6. 6Put comparable-protection terms in place for processing transfers, including cross-border.

Frequently asked questions

Does PIPEDA prohibit storing Canadian personal information abroad?

No. It requires the transferring organisation to remain accountable, ensure comparable protection and be transparent that information may be processed outside Canada.

Can the Privacy Commissioner fine my organisation under PIPEDA?

PIPEDA operates on an ombudsman model. Findings and recommendations are issued, with court proceedings available for remedies; some provincial regimes do provide direct penalties.

Official sources

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.