Overview
PIPEDA was enacted in 2000 and has applied to commercial activity across Canada since 2004. Part 1 sets the privacy rules, and Schedule 1 brings in the 10 principles of the CSA Model Code for the Protection of Personal Information. Organizations need meaningful consent, may collect only what they need for identified purposes, must protect information with safeguards suited to its sensitivity, and must let people see and correct their records. The law is principle based. It doesn't prescribe specific security controls, so the OPC judges safeguards against the sensitivity of the data and the circumstances of each case.
Amendments that took effect on November 1, 2018 added mandatory breach reporting. When a breach of security safeguards creates a real risk of significant harm, the organization must report it to the OPC, notify affected individuals as soon as feasible, and tell other organizations or government institutions that could reduce the harm. Records matter too. Every breach must be recorded and the record kept for 24 months, whether or not it met the harm threshold. Knowingly failing to report, notify, or keep records is an offence, with fines of up to $100,000.
PIPEDA is still the law in force. Bill C-11 (2020) and Bill C-27 (2022) would have replaced Part 1 with a Consumer Privacy Protection Act, but both died on the order paper, C-27 when the parliamentary session ended on January 6, 2025. On June 15, 2026 the government introduced Bill C-36, the Protecting Privacy and Consumer Data Act. As of October 11, 2026 it's at second reading in the House of Commons. If passed as introduced, it would move private-sector privacy oversight from the OPC to a proposed Digital Safety and Data Protection Commission of Canada.
Who it applies to in Canada
Private-sector organizations that collect, use, or disclose personal information in the course of commercial activity, except for activity inside Alberta, British Columbia, and Quebec, which have substantially similar laws. It also covers federally regulated businesses such as banks, airlines, and telecommunications companies, including their employee information, and personal information that crosses provincial or national borders.
PIPEDA is the default federal privacy law for Canadian businesses, and interprovincial or international data flows bring organizations in every province under it. The Office of the Privacy Commissioner of Canada (OPC) investigates complaints and receives mandatory breach reports.
Controls at a glance
Schedule 1 sets out 10 fair information principles, and Division 1.1 of Part 1 adds the breach of security safeguards obligations.
Principle 1: Accountability
- Designate a person accountable for compliance
- Stay responsible for data sent to service providers
- Adopt policies, training, and complaint procedures
Principle 2: Identifying purposes
- Identify purposes before or at collection
- Document the purposes
- Identify any new purpose before using data for it
Principle 3: Consent
- Obtain knowledge and consent for collection, use, and disclosure
- Use express consent for sensitive information
- Let individuals withdraw consent, subject to legal limits
Principle 4: Limiting collection
- Collect only what the identified purposes need
- Collect by fair and lawful means
- Avoid indiscriminate collection
Principle 5: Limiting use, disclosure, and retention
- Use and disclose only for identified purposes
- Keep data only as long as needed
- Destroy or anonymize data that is no longer required
Principle 6: Accuracy
- Keep data accurate, complete, and up to date
- Match accuracy to how the data will be used
- Avoid routine updates without a purpose
Principle 7: Safeguards
- Protect data against loss, theft, and unauthorized access
- Scale safeguards to the sensitivity of the data
- Combine physical, organizational, and technical measures
- Train staff on confidentiality
Principle 8: Openness
- Publish privacy policies and practices in plain language
- Name a contact for privacy questions
- Explain what data is held and how it's used
Principle 9: Individual access
- Tell individuals what data is held about them
- Give access, generally within 30 days
- Correct inaccurate information when shown
Principle 10: Challenging compliance
- Provide a simple complaint procedure
- Investigate every complaint
- Fix policies when a complaint is justified
Breach of security safeguards
- Assess real risk of significant harm for each breach
- Report qualifying breaches to the OPC
- Notify affected individuals as soon as feasible
- Notify organizations that can reduce the harm
- Keep a record of every breach for 24 months
Certification and assessment
There is no certification under PIPEDA. The OPC investigates complaints, can audit an organization's practices on reasonable grounds, and can enter into compliance agreements, but it can't issue fines or binding orders. Complainants or the Commissioner can apply to the Federal Court, which can order changes and award damages.
Dates to know
- 2001-01-01
- Part 1 begins to apply to federal works, undertakings, and businesses
- 2004-01-01
- PIPEDA applies to all commercial activity not covered by a substantially similar provincial law
- 2018-11-01
- Mandatory breach reporting, notification, and record-keeping take effect
- 2025-01-06
- Bill C-27 (Consumer Privacy Protection Act) dies when the parliamentary session ends
- 2026-06-15
- Bill C-36, the Protecting Privacy and Consumer Data Act, introduced in the House of Commons
Resources
Official texts and free tools for PIPEDA. Links open the publisher’s site.
- The Personal Information Protection and Electronic Documents Act (PIPEDA), Office of the Privacy Commissioner of Canada
- Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Justice Laws Website
- PIPEDA fair information principles, Office of the Privacy Commissioner of Canadaguidance
- What you need to know about mandatory reporting of breaches of security safeguards, Office of the Privacy Commissioner of Canadaguidance
- Report a privacy breach at your organization, Office of the Privacy Commissioner of Canadatool
- PIPEDA compliance help, Office of the Privacy Commissioner of Canadaguidance
Need help? Browse the directory or read the guides.
References
- Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Justice Laws Website
- Breach of Security Safeguards Regulations (SOR/2018-64), Justice Laws Website
- Bill C-36 (45th Parliament, 1st Session), LEGISinfo, Parliament of Canada
- Statement by the Privacy Commissioner of Canada on Bill C-36, Office of the Privacy Commissioner of Canada
- Bill C-27 (44th Parliament, 1st Session), LEGISinfo, Parliament of Canada
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.