home / frameworks / pipeda

// Canadian privacy and cyber law

Personal Information Protection and Electronic Documents Act (PIPEDA)

PIPEDA is Canada's federal private-sector privacy law, built on 10 fair information principles. Since November 1, 2018, organizations must report breaches that pose a real risk of significant harm to the OPC, notify the people affected, and keep a record of every breach.

Canada (federal)Mandatory for organizations in scope

Overview

PIPEDA was enacted in 2000 and has applied to commercial activity across Canada since 2004. Part 1 sets the privacy rules, and Schedule 1 brings in the 10 principles of the CSA Model Code for the Protection of Personal Information. Organizations need meaningful consent, may collect only what they need for identified purposes, must protect information with safeguards suited to its sensitivity, and must let people see and correct their records. The law is principle based. It doesn't prescribe specific security controls, so the OPC judges safeguards against the sensitivity of the data and the circumstances of each case.

Amendments that took effect on November 1, 2018 added mandatory breach reporting. When a breach of security safeguards creates a real risk of significant harm, the organization must report it to the OPC, notify affected individuals as soon as feasible, and tell other organizations or government institutions that could reduce the harm. Records matter too. Every breach must be recorded and the record kept for 24 months, whether or not it met the harm threshold. Knowingly failing to report, notify, or keep records is an offence, with fines of up to $100,000.

PIPEDA is still the law in force. Bill C-11 (2020) and Bill C-27 (2022) would have replaced Part 1 with a Consumer Privacy Protection Act, but both died on the order paper, C-27 when the parliamentary session ended on January 6, 2025. On June 15, 2026 the government introduced Bill C-36, the Protecting Privacy and Consumer Data Act. As of October 11, 2026 it's at second reading in the House of Commons. If passed as introduced, it would move private-sector privacy oversight from the OPC to a proposed Digital Safety and Data Protection Commission of Canada.

Who it applies to in Canada

Private-sector organizations that collect, use, or disclose personal information in the course of commercial activity, except for activity inside Alberta, British Columbia, and Quebec, which have substantially similar laws. It also covers federally regulated businesses such as banks, airlines, and telecommunications companies, including their employee information, and personal information that crosses provincial or national borders.

PIPEDA is the default federal privacy law for Canadian businesses, and interprovincial or international data flows bring organizations in every province under it. The Office of the Privacy Commissioner of Canada (OPC) investigates complaints and receives mandatory breach reports.

Controls at a glance

Schedule 1 sets out 10 fair information principles, and Division 1.1 of Part 1 adds the breach of security safeguards obligations.

Principle 1: Accountability

  • Designate a person accountable for compliance
  • Stay responsible for data sent to service providers
  • Adopt policies, training, and complaint procedures

Principle 2: Identifying purposes

  • Identify purposes before or at collection
  • Document the purposes
  • Identify any new purpose before using data for it

Principle 3: Consent

  • Obtain knowledge and consent for collection, use, and disclosure
  • Use express consent for sensitive information
  • Let individuals withdraw consent, subject to legal limits

Principle 4: Limiting collection

  • Collect only what the identified purposes need
  • Collect by fair and lawful means
  • Avoid indiscriminate collection

Principle 5: Limiting use, disclosure, and retention

  • Use and disclose only for identified purposes
  • Keep data only as long as needed
  • Destroy or anonymize data that is no longer required

Principle 6: Accuracy

  • Keep data accurate, complete, and up to date
  • Match accuracy to how the data will be used
  • Avoid routine updates without a purpose

Principle 7: Safeguards

  • Protect data against loss, theft, and unauthorized access
  • Scale safeguards to the sensitivity of the data
  • Combine physical, organizational, and technical measures
  • Train staff on confidentiality

Principle 8: Openness

  • Publish privacy policies and practices in plain language
  • Name a contact for privacy questions
  • Explain what data is held and how it's used

Principle 9: Individual access

  • Tell individuals what data is held about them
  • Give access, generally within 30 days
  • Correct inaccurate information when shown

Principle 10: Challenging compliance

  • Provide a simple complaint procedure
  • Investigate every complaint
  • Fix policies when a complaint is justified

Breach of security safeguards

  • Assess real risk of significant harm for each breach
  • Report qualifying breaches to the OPC
  • Notify affected individuals as soon as feasible
  • Notify organizations that can reduce the harm
  • Keep a record of every breach for 24 months

Certification and assessment

There is no certification under PIPEDA. The OPC investigates complaints, can audit an organization's practices on reasonable grounds, and can enter into compliance agreements, but it can't issue fines or binding orders. Complainants or the Commissioner can apply to the Federal Court, which can order changes and award damages.

Dates to know

2001-01-01
Part 1 begins to apply to federal works, undertakings, and businesses
2004-01-01
PIPEDA applies to all commercial activity not covered by a substantially similar provincial law
2018-11-01
Mandatory breach reporting, notification, and record-keeping take effect
2025-01-06
Bill C-27 (Consumer Privacy Protection Act) dies when the parliamentary session ends
2026-06-15
Bill C-36, the Protecting Privacy and Consumer Data Act, introduced in the House of Commons

Resources

Official texts and free tools for PIPEDA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Justice Laws Website
  2. Breach of Security Safeguards Regulations (SOR/2018-64), Justice Laws Website
  3. Bill C-36 (45th Parliament, 1st Session), LEGISinfo, Parliament of Canada
  4. Statement by the Privacy Commissioner of Canada on Bill C-36, Office of the Privacy Commissioner of Canada
  5. Bill C-27 (44th Parliament, 1st Session), LEGISinfo, Parliament of Canada