home / frameworks / gdpr

// Foreign laws with Canadian reach

General Data Protection Regulation (EU) 2016/679

The EU's data protection law applies to Canadian companies that offer goods or services to people in the EU or monitor them. It requires lawful processing, data subject rights, security, 72-hour breach notice, and in many cases an EU representative.

European Union and European Economic Area

Overview

The General Data Protection Regulation (EU) 2016/679 has applied since May 25, 2018. It governs the processing of personal data about people in the European Union and the wider European Economic Area. Its reach goes well past EU borders. Under Article 3(2), a Canadian company with no EU office is still covered when it offers goods or services to people in the EU, paid or free, or monitors their behaviour there, for example through tracking and profiling on a website or app. The European Data Protection Board's guidelines on territorial scope explain how to tell whether an offer targets the EU, using signals such as EU currencies, languages, and delivery options.

A covered company without an EU establishment generally has to appoint a representative in a member state where its data subjects are (Article 27). The exception is narrow. It covers occasional processing that doesn't involve large-scale sensitive data and is unlikely to put people at risk. A company without an EU establishment also gets no lead authority under the one-stop-shop, so it can deal with the supervisory authority of each member state where people are affected. Breaches must be reported to the supervisory authority within 72 hours of becoming aware of them, unless the breach is unlikely to result in a risk to people. Fines reach €20 million or 4% of worldwide annual turnover, whichever is higher.

Canada has held an adequacy decision since December 20, 2001 (Decision 2002/2/EC). It lets personal data flow from the EU to recipients subject to PIPEDA without extra safeguards. On January 15, 2024 the Commission's first review found that Canada still provides adequate protection, citing PIPEDA amendments on consent and breach reporting and the work of the Office of the Privacy Commissioner. Data sent to organizations outside PIPEDA's scope, such as most public bodies, still needs another transfer tool like standard contractual clauses. Adequacy covers transfers only. On November 19, 2025 the Commission proposed a Digital Omnibus (COM(2025) 837) that would change parts of the GDPR, including when and how breaches are notified, and as of October 2026 it's still before the European Parliament and has not been adopted.

Who it applies to in Canada

Controllers and processors established in the EU, and organizations outside the EU that offer goods or services to people in the EU or monitor their behaviour there.

Canadian companies with EU customers, users, or website visitors they track fall under Article 3(2). Canada's adequacy decision lets EU data flow to recipients subject to PIPEDA, but it doesn't remove GDPR duties for companies that are in scope.

Controls at a glance

The GDPR is organized around principles, lawful bases, individual rights, controller and processor duties, and rules on transfers outside the EU.

Principles (Article 5)

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability, meaning the controller can show compliance

Lawful bases (Article 6)

  • Consent that is freely given, specific, informed, and unambiguous
  • Performance of a contract with the individual
  • Compliance with a legal obligation
  • Protection of vital interests
  • Public task or official authority
  • Legitimate interests balanced against the individual's rights

Special categories of data also need an Article 9 condition.

Data subject rights (Articles 12 to 22)

  • Clear information at collection (Articles 13 and 14)
  • Access to personal data and a copy
  • Rectification of inaccurate data
  • Erasure in defined cases
  • Restriction of processing
  • Data portability
  • Objection, including an absolute right against direct marketing
  • Safeguards on solely automated decisions with significant effects
  • Respond within one month, extendable in some cases

Security of processing (Article 32)

  • Measures matched to risk and the state of the art
  • Pseudonymization and encryption where appropriate
  • Ongoing confidentiality, integrity, availability, and resilience
  • Restore access to data promptly after an incident
  • Regularly test and evaluate security measures
  • Bind processors by contract under Article 28

Breach notification (Articles 33 and 34)

  • Notify the supervisory authority within 72 hours
  • No notice needed if a breach is unlikely to cause risk
  • Give reasons for any notice later than 72 hours
  • Processors tell controllers without undue delay
  • Tell affected people without undue delay when risk is high
  • Document every breach, notified or not

Accountability and DPIAs (Articles 24 to 39)

  • Data protection by design and by default
  • Records of processing activities
  • DPIA before likely high-risk processing
  • DPIA for large-scale sensitive data or systematic public monitoring
  • Consult the authority when high residual risk remains
  • Appoint a data protection officer where required

International transfers (Chapter V)

  • Transfers allowed to countries with an adequacy decision
  • Canada's decision covers recipients subject to PIPEDA
  • Standard contractual clauses for other transfers
  • Binding corporate rules for intra-group transfers
  • Assess the destination's laws when relying on safeguards
  • Article 49 derogations for limited, occasional cases

Non-EU organizations (Articles 3 and 27)

  • Covered when offering goods or services to people in the EU
  • Covered when monitoring behaviour that takes place in the EU
  • Appoint an EU representative by written mandate
  • Representative deals with authorities and individuals
  • Narrow exemption for occasional, low-risk processing

Certification and assessment

Compliance is shown through records of processing, DPIAs, contracts, policies, and breach logs that authorities can request at any time. Authorities investigate complaints and breaches and can order changes or impose fines. Article 42 certification schemes exist but are voluntary and rare, and the Standards Council of Canada doesn't accredit GDPR certification bodies.

Dates to know

2001-12-20
Commission adopts the adequacy decision for Canada (Decision 2002/2/EC) covering recipients subject to PIPEDA
2016-04-27
GDPR adopted
2018-05-25
GDPR becomes applicable
2024-01-15
Commission's first review confirms Canada's adequacy decision continues
2025-11-19
Commission proposes the Digital Omnibus (COM(2025) 837) with GDPR amendments, not adopted as of October 2026

Resources

Official texts and free tools for GDPR. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Regulation (EU) 2016/679 (GDPR), EUR-Lex, Publications Office of the European Union
  2. Commission finds that EU personal data flows can continue with 11 third countries and territories, European Commission
  3. Data protection adequacy for non-EU countries, European Commission
  4. Procedure file 2025/0360(COD), Digital Omnibus, European Parliament Legislative Observatory