Regulations › Rest of world

PIPEDA

Personal Information Protection and Electronic Documents Act (Canada)

In force privacy
WhenIn effect since 1 January 2001
Who enforces itOffice of the Privacy Commissioner of Canada
Who it applies toPrivate-sector organizations handling personal information in commercial activity, outside provinces with substantially similar laws.

Canada's federal private-sector privacy law, built on ten fair information principles.

The law in brief

PIPEDA is Canada's federal privacy law for the private sector. It is built on ten fair information principles, with meaningful consent at its center, and it includes mandatory reporting of breaches that create a real risk of significant harm.

It applies across Canada except where a province has a substantially similar law for activity within that province, as Quebec, British Columbia and Alberta do. Cross-border and interprovincial activity stays under PIPEDA.

Who it applies to

  • Private-sector organizations that collect, use or disclose personal information in the course of commercial activity.
  • Federally regulated works and businesses, such as banks, airlines, telecommunications and broadcasting, including for their employees' information.
  • Personal information that crosses provincial or national borders in commercial activity.
  • Organizations outside Canada with a real and substantial connection to Canada.

What it requires

The ten fair information principles

Comply with the principles in Schedule 1: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

Meaningful consent

Obtain valid consent: individuals must reasonably understand the nature, purpose and consequences of the collection, use or disclosure they consent to.

Appropriate purposes

Collect, use or disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances.

Report and notify breaches

Report to the Commissioner, and notify affected individuals as soon as feasible, any breach of security safeguards involving personal information that creates a real risk of significant harm, and keep records of all breaches for 24 months.

People's rights

Individuals can access their personal information and challenge its accuracy, withdraw consent subject to legal or contractual restrictions, and complain to the Office of the Privacy Commissioner, then apply to the Federal Court.

Enforcement and penalties

The Privacy Commissioner investigates and issues findings and recommendations but cannot fine. Knowingly failing to report a breach, notify individuals or keep breach records is an offence with fines of up to C$100,000. The Federal Court can order compliance and award damages.

What's changing

Reform stalled. Bill C-27, which would have replaced PIPEDA with a new Consumer Privacy Protection Act, died when Parliament was prorogued in January 2025. Regulatory Watch reports any new federal privacy bill.

What to do first

  1. Name the person accountable for privacy compliance.
  2. Check consent is meaningful: clear about what, why, with whom, and the risks, with express consent for sensitive information.
  3. Map cross-border transfers and tell people when their data may be processed outside Canada.
  4. Set up breach assessment against the real risk of significant harm test, and keep a record of every breach for 24 months.
  5. Check provincial laws in Quebec, British Columbia and Alberta, and health information laws.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources