PIPEDA
Personal Information Protection and Electronic Documents Act (Canada)
Canada's federal private-sector privacy law, built on ten fair information principles.
The law in brief
PIPEDA is Canada's federal privacy law for the private sector. It is built on ten fair information principles, with meaningful consent at its center, and it includes mandatory reporting of breaches that create a real risk of significant harm.
It applies across Canada except where a province has a substantially similar law for activity within that province, as Quebec, British Columbia and Alberta do. Cross-border and interprovincial activity stays under PIPEDA.
Who it applies to
- Private-sector organizations that collect, use or disclose personal information in the course of commercial activity.
- Federally regulated works and businesses, such as banks, airlines, telecommunications and broadcasting, including for their employees' information.
- Personal information that crosses provincial or national borders in commercial activity.
- Organizations outside Canada with a real and substantial connection to Canada.
What it requires
The ten fair information principles
Comply with the principles in Schedule 1: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Meaningful consent
Obtain valid consent: individuals must reasonably understand the nature, purpose and consequences of the collection, use or disclosure they consent to.
Appropriate purposes
Collect, use or disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances.
Report and notify breaches
Report to the Commissioner, and notify affected individuals as soon as feasible, any breach of security safeguards involving personal information that creates a real risk of significant harm, and keep records of all breaches for 24 months.
People's rights
Individuals can access their personal information and challenge its accuracy, withdraw consent subject to legal or contractual restrictions, and complain to the Office of the Privacy Commissioner, then apply to the Federal Court.
Enforcement and penalties
The Privacy Commissioner investigates and issues findings and recommendations but cannot fine. Knowingly failing to report a breach, notify individuals or keep breach records is an offence with fines of up to C$100,000. The Federal Court can order compliance and award damages.
What's changing
Reform stalled. Bill C-27, which would have replaced PIPEDA with a new Consumer Privacy Protection Act, died when Parliament was prorogued in January 2025. Regulatory Watch reports any new federal privacy bill.
What to do first
- Name the person accountable for privacy compliance.
- Check consent is meaningful: clear about what, why, with whom, and the risks, with express consent for sensitive information.
- Map cross-border transfers and tell people when their data may be processed outside Canada.
- Set up breach assessment against the real risk of significant harm test, and keep a record of every breach for 24 months.
- Check provincial laws in Quebec, British Columbia and Alberta, and health information laws.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) Justice Laws Website · Official text or regulator