Provincial Compliance
Part of the AODA guide

Ontario Privacy Rules: PIPEDA, PHIPA and AODA Explained

Which privacy rules apply to an Ontario business: PIPEDA for commercial activity, PHIPA for health information, and AODA for accessibility.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
12 min read
Ontario Privacy Law
PHIPA Compliance
Ontario PIPEDA
Toronto Business Privacy
Ontario SMB Compliance

Ontario is Canada's largest business hub — and it operates under a more complex privacy law framework than most provinces. Unlike Alberta and BC, Ontario does not have its own substantially similar private-sector privacy law. That means federal PIPEDA applies directly to most Ontario commercial activities. But for health information, Ontario's PHIPA creates an entirely separate compliance obligation.

Last updated: April 2026

The Ontario Privacy Law Framework

Ontario businesses may face obligations under several statutes:

LawApplies To
PIPEDA (federal)All private-sector commercial activities in Ontario
PHIPA — Personal Health Information Protection ActHealth information custodians (hospitals, doctors, dentists, pharmacists, etc.)
MFIPPA — Municipal Freedom of Information and Protection of Privacy ActMunicipal government and local agencies
FIPPA — Freedom of Information and Protection of Privacy ActProvincial government and public bodies

For private-sector businesses, the primary laws are PIPEDA and (if you handle patient/client health information as a healthcare custodian) PHIPA.

PIPEDA in Ontario: No Provincial Alternative

Because Ontario lacks its own substantially similar private-sector privacy law, PIPEDA applies directly to all Ontario commercial activities — including activities that would be covered by PIPA in Alberta or BC.

This means the same PIPEDA obligations apply:

  • Designate a Privacy Officer
  • Publish an accessible privacy policy
  • Obtain meaningful consent for data collection
  • Implement appropriate security safeguards
  • Respond to access requests within 30 days
  • Report qualifying breaches to the OPC

The OPC enforces PIPEDA for Ontario businesses. Ontario does not have a separate provincial private-sector privacy regulator.

PHIPA: Ontario's Health Privacy Law

If your business is a health information custodian (HIC), PHIPA is the primary law governing your handling of personal health information (PHI).

Who is a health information custodian under PHIPA?

  • Regulated health professionals: physicians, dentists, nurses, pharmacists, physiotherapists, chiropractors, optometrists, psychologists
  • Hospitals, long-term care homes, clinics
  • Medical laboratories and specimen collection centres
  • Ambulance services
  • Pharmacies, long-term care homes and retirement homes

Note: Employers are generally NOT health information custodians under PHIPA simply because they have employees. PIPEDA covers employee personal information only in connection with the operation of a federal work, undertaking or business (PIPEDA s. 4(1)(b)), so for most provincially regulated Ontario employers, employee health information is governed by employment law rather than PHIPA or PIPEDA.

Key PHIPA Obligations

Consent under PHIPA: PHIPA uses a "consent to treatment" model. A health information custodian may collect, use, or disclose PHI:

  • With express or implied consent from the individual
  • For the purpose of providing or assisting in providing healthcare
  • As authorised by PHIPA (law enforcement, public health, legal proceedings)

For purposes beyond direct healthcare, specific rules apply: marketing requires express consent (s. 33); fundraising requires express consent, or implied consent limited to the individual's name and prescribed contact information (s. 32); and disclosure to researchers requires, among other things, a research plan approved by a research ethics board (s. 44).

Individual rights under PHIPA:

  • Right of access to their own PHI (30 days to respond, extendable by up to 30 days — s. 54)
  • Right to correct inaccuracies
  • Right to withdraw consent
  • Right to complain to the Information and Privacy Commissioner of Ontario (IPC)

Breach notification under PHIPA: Health information custodians must:

  1. Notify affected individuals "at the first reasonable opportunity" if their PHI is stolen, lost, or used or disclosed without authority, including a statement that they may complain to the IPC (PHIPA s. 12(2))
  2. Notify the IPC at the first reasonable opportunity when the prescribed circumstances apply — for example, theft, deliberate unauthorized use or disclosure, a pattern of similar breaches, or a significant breach (O. Reg. 329/04, s. 6.3)
  3. Report annually to the IPC the number of thefts, losses and unauthorized uses or disclosures in the previous calendar year (O. Reg. 329/04, s. 6.4)

The IPC enforces PHIPA and can conduct reviews and make orders.

Recent Ontario Privacy Developments

Potential Ontario Private Sector Privacy Law

The Ontario government consulted in 2020 on strengthening private-sector privacy protections, including a possible provincial privacy law. As of 2026, no such law has been enacted, so PIPEDA continues to govern. Monitor the Ontario government for updates.

AI Use in Healthcare

If you use AI for clinical decision support, patient triage, or health information processing, review the IPC's guidance, such as AI Scribes: Key Considerations for the Health Sector (January 2026). (The federal Artificial Intelligence and Data Act proposed in Bill C-27 was never enacted.) (The federal Artificial Intelligence and Data Act proposed in Bill C-27 was never enacted.)

Practical Compliance for Ontario Businesses

Non-Healthcare Businesses (PIPEDA applies)

Your compliance programme follows standard PIPEDA requirements:

  • Privacy Officer, privacy policy, consent, security, breach response, access requests
  • See our PIPEDA Compliance Checklist for the full framework

Healthcare Businesses (PHIPA + PIPEDA may both apply)

You need to satisfy both PHIPA for PHI and PIPEDA for non-health personal information collected in commercial activities (administrative data, business partner information).

Practical approach:

  1. Build a PHIPA-compliant programme for PHI (your primary obligation)
  2. Ensure the remaining personal information (such as vendor information) is covered by PIPEDA-compliant policies
  3. One Privacy Officer can manage both frameworks
  4. Train clinical staff on PHIPA; train administrative staff on both PHIPA and PIPEDA

Key Compliance Resources in Ontario

  • IPC Ontario (PHIPA enforcement): ipc.on.ca
  • OPC Canada (PIPEDA enforcement): priv.gc.ca
  • College of Physicians and Surgeons of Ontario: PHIPA guidance for physicians
  • Ontario Dental Association: PHIPA guidance for dentists

Frequently Asked Questions

Q: My Ontario business does not deal in healthcare. Is PHIPA relevant to me? A: Not directly. PHIPA applies to health information custodians. If you're a retail business, tech company, or professional services firm, PIPEDA governs your privacy obligations.

Q: My company has an Employee Assistance Programme (EAP) that provides health support. Does PHIPA apply? A: The EAP provider (typically a third-party health services company) is likely a health information custodian subject to PHIPA for the health information it collects. As an employer, you are not a health information custodian simply by offering EAP access, but you must handle employee health information carefully under employment law (and under PIPEDA if you are a federal work, undertaking or business).

Q: Are therapists and social workers in Ontario covered by PHIPA? A: Regulated health professions (including registered psychotherapists and registered social workers) are health information custodians under PHIPA.

Q: Is there a mandatory waiting period for breach notification under PHIPA? A: No — notification must occur "at the first reasonable opportunity," which means as quickly as practically possible after discovering the breach.


One Platform for Ontario's Full Privacy Framework

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — Ontario compliance made simple.

Related reading: PIPEDA Compliance Guide | Healthcare PIPEDA Compliance | AODA Website Compliance 2026 | IPC Ontario

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.