Overview
The General Data Protection Regulation (EU) 2016/679 has applied since May 25, 2018. It governs the processing of personal data about people in the European Union and the wider European Economic Area. Its reach goes well past EU borders. Under Article 3(2), a Canadian company with no EU office is still covered when it offers goods or services to people in the EU, paid or free, or monitors their behaviour there, for example through tracking and profiling on a website or app. The European Data Protection Board's guidelines on territorial scope explain how to tell whether an offer targets the EU, using signals such as EU currencies, languages, and delivery options.
A covered company without an EU establishment generally has to appoint a representative in a member state where its data subjects are (Article 27). The exception is narrow. It covers occasional processing that doesn't involve large-scale sensitive data and is unlikely to put people at risk. A company without an EU establishment also gets no lead authority under the one-stop-shop, so it can deal with the supervisory authority of each member state where people are affected. Breaches must be reported to the supervisory authority within 72 hours of becoming aware of them, unless the breach is unlikely to result in a risk to people. Fines reach €20 million or 4% of worldwide annual turnover, whichever is higher.
Canada has held an adequacy decision since December 20, 2001 (Decision 2002/2/EC). It lets personal data flow from the EU to recipients subject to PIPEDA without extra safeguards. On January 15, 2024 the Commission's first review found that Canada still provides adequate protection, citing PIPEDA amendments on consent and breach reporting and the work of the Office of the Privacy Commissioner. Data sent to organizations outside PIPEDA's scope, such as most public bodies, still needs another transfer tool like standard contractual clauses. Adequacy covers transfers only. On November 19, 2025 the Commission proposed a Digital Omnibus (COM(2025) 837) that would change parts of the GDPR, including when and how breaches are notified, and as of October 2026 it's still before the European Parliament and has not been adopted.
Who it applies to in Canada
Controllers and processors established in the EU, and organizations outside the EU that offer goods or services to people in the EU or monitor their behaviour there.
Canadian companies with EU customers, users, or website visitors they track fall under Article 3(2). Canada's adequacy decision lets EU data flow to recipients subject to PIPEDA, but it doesn't remove GDPR duties for companies that are in scope.
Controls at a glance
The GDPR is organized around principles, lawful bases, individual rights, controller and processor duties, and rules on transfers outside the EU.
Principles (Article 5)
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability, meaning the controller can show compliance
Lawful bases (Article 6)
- Consent that is freely given, specific, informed, and unambiguous
- Performance of a contract with the individual
- Compliance with a legal obligation
- Protection of vital interests
- Public task or official authority
- Legitimate interests balanced against the individual's rights
Special categories of data also need an Article 9 condition.
Data subject rights (Articles 12 to 22)
- Clear information at collection (Articles 13 and 14)
- Access to personal data and a copy
- Rectification of inaccurate data
- Erasure in defined cases
- Restriction of processing
- Data portability
- Objection, including an absolute right against direct marketing
- Safeguards on solely automated decisions with significant effects
- Respond within one month, extendable in some cases
Security of processing (Article 32)
- Measures matched to risk and the state of the art
- Pseudonymization and encryption where appropriate
- Ongoing confidentiality, integrity, availability, and resilience
- Restore access to data promptly after an incident
- Regularly test and evaluate security measures
- Bind processors by contract under Article 28
Breach notification (Articles 33 and 34)
- Notify the supervisory authority within 72 hours
- No notice needed if a breach is unlikely to cause risk
- Give reasons for any notice later than 72 hours
- Processors tell controllers without undue delay
- Tell affected people without undue delay when risk is high
- Document every breach, notified or not
Accountability and DPIAs (Articles 24 to 39)
- Data protection by design and by default
- Records of processing activities
- DPIA before likely high-risk processing
- DPIA for large-scale sensitive data or systematic public monitoring
- Consult the authority when high residual risk remains
- Appoint a data protection officer where required
International transfers (Chapter V)
- Transfers allowed to countries with an adequacy decision
- Canada's decision covers recipients subject to PIPEDA
- Standard contractual clauses for other transfers
- Binding corporate rules for intra-group transfers
- Assess the destination's laws when relying on safeguards
- Article 49 derogations for limited, occasional cases
Non-EU organizations (Articles 3 and 27)
- Covered when offering goods or services to people in the EU
- Covered when monitoring behaviour that takes place in the EU
- Appoint an EU representative by written mandate
- Representative deals with authorities and individuals
- Narrow exemption for occasional, low-risk processing
Certification and assessment
Compliance is shown through records of processing, DPIAs, contracts, policies, and breach logs that authorities can request at any time. Authorities investigate complaints and breaches and can order changes or impose fines. Article 42 certification schemes exist but are voluntary and rare, and the Standards Council of Canada doesn't accredit GDPR certification bodies.
Dates to know
- 2001-12-20
- Commission adopts the adequacy decision for Canada (Decision 2002/2/EC) covering recipients subject to PIPEDA
- 2016-04-27
- GDPR adopted
- 2018-05-25
- GDPR becomes applicable
- 2024-01-15
- Commission's first review confirms Canada's adequacy decision continues
- 2025-11-19
- Commission proposes the Digital Omnibus (COM(2025) 837) with GDPR amendments, not adopted as of October 2026
Resources
Official texts and free tools for GDPR. Links open the publisher’s site.
- Regulation (EU) 2016/679 (GDPR), official text, EUR-Lex, Publications Office of the European Union
- Data protection adequacy for non-EU countries, European Commission
- The Personal Information Protection and Electronic Documents Act (PIPEDA), Office of the Privacy Commissioner of Canada
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Boardguidance
- Guidelines 9/2022 on personal data breach notification under GDPR, European Data Protection Boardguidance
- Data protection guide for small business, European Data Protection Boardguidance
Need help? Browse the directory or read the guides.
References
- Regulation (EU) 2016/679 (GDPR), EUR-Lex, Publications Office of the European Union
- Commission finds that EU personal data flows can continue with 11 third countries and territories, European Commission
- Data protection adequacy for non-EU countries, European Commission
- Procedure file 2025/0360(COD), Digital Omnibus, European Parliament Legislative Observatory
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.