PIPEDA Consent Requirements: Express vs Implied for Canadian Businesses
How PIPEDA consent works: when express consent is required, when implied consent is enough, and how to document that consent was meaningful.
Consent is the backbone of Canada's privacy law framework. Under PIPEDA, you generally need an individual's consent before collecting, using, or disclosing their personal information. But "consent" isn't a single concept — Canadian privacy law distinguishes between express and implied consent, and using the wrong type at the wrong time can expose your business to significant liability.
This guide explains the consent framework clearly, with practical examples for Canadian businesses.
Last updated: April 2026
The PIPEDA Consent Principle
PIPEDA's Consent Principle (Principle 3) states: "The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate."
Two critical elements: knowledge (the person understands what they're consenting to) and consent (they actively agree, or at least don't object when given the opportunity).
Consent under PIPEDA must be:
- Informed — individuals understand what they're consenting to
- Freely given — not coerced or bundled with unrelated conditions
- Specific — tied to specific purposes, not a blanket approval
- Meaningful — the person has a real ability to say no
Express Consent vs Implied Consent
Express Consent
Express consent means the individual explicitly agrees — verbally, in writing, or by checking a box. It leaves no doubt that the person has consented.
When is express consent required?
- Collection of sensitive personal information: health records, financial data, ethnic origin, political views, sexual orientation, religious beliefs
- Use of personal information for a new purpose not covered by the original consent
- Disclosing personal information to third parties for their own purposes
- Signing individuals up for commercial electronic messages (CASL also requires this)
Examples of express consent mechanisms:
- A patient signing a consent form before a medical consultation
- A customer ticking a box: "I agree to receive promotional emails"
- An employee signing an acknowledgement that their work communications may be monitored
- An app user selecting "Allow" when asked for location access
What doesn't count as express consent:
- Pre-ticked checkboxes
- Terms buried in fine print that aren't brought to the user's attention
- "By using our service, you consent to..." without a clear affirmative action
- Opt-out mechanisms presented as consent
Implied Consent
Implied consent exists when consent can be reasonably inferred from the circumstances and the nature of the relationship, even without an explicit statement.
When can you rely on implied consent?
- Collecting a customer's name and address for delivering an order they placed
- Using a business contact's card details to follow up on a meeting they requested
- Sending a receipt to the email address provided at checkout
- Sharing relevant information with an employee's health insurer when they've submitted a disability claim
The key test for implied consent: Would a reasonable person in the individual's position expect this collection and use to occur given the circumstances?
The Sensitivity Scale: Matching Consent to the Data
Not all personal information is equally sensitive. PIPEDA expects your consent mechanism to match the sensitivity of the information:
| Information Type | Sensitivity | Consent Required |
|---|---|---|
| Name and contact details | Low | Implied (in most contexts) |
| Purchase history | Low-Medium | Implied (for fulfillment); Express (for profiling) |
| Financial data | High | Express |
| Health and medical records | Very High | Express (written preferred) |
| Biometric data | Very High | Express |
| Sexual orientation, religion, ethnicity | Very High | Express |
| Criminal history | Very High | Express |
| Location data (continuous tracking) | High | Express |
Bundling Consent: What's Allowed and What's Not
A common trap for businesses is bundling consent — requiring consent to unrelated data uses as a condition of service.
Generally not permitted:
- "To create an account, you must consent to receiving our marketing emails"
- "By purchasing, you agree to us sharing your data with our advertising partners"
- Refusing service if someone declines non-essential consent
The OPC's guidance: Consent for purposes necessary to provide a product or service may be bundled with the agreement to receive that service. But consent for uses that go beyond what's necessary to provide the service must be separate and optional.
Practical example: A retailer can require your shipping address to deliver an order (necessary), but cannot require you to consent to targeted advertising as a condition of purchase (not necessary).
Withdrawal of Consent
Individuals have the right to withdraw consent at any time, subject to legal or contractual restrictions. Once consent is withdrawn, you must stop the collection, use, or disclosure — typically within a reasonable timeframe.
For email marketing, CASL sets a specific standard: you must honour unsubscribes within 10 business days.
Your business should:
- Have a clear process for receiving and acting on consent withdrawals
- Communicate what will happen when consent is withdrawn
- Document all withdrawals with timestamps
- Implement technical mechanisms to stop data processing promptly
Consent for Children's Data
PIPEDA does not set a specific age of consent for data processing. However, the OPC's position is that children cannot provide meaningful consent for complex data uses. In practice:
- Marketing-related consent should come from a parent or guardian for children under 13
- For teenagers (13–18), consent mechanisms must be age-appropriate and clear
- Quebec's Law 25 is more prescriptive — it requires parental consent for commercial processing of data belonging to minors
CASL and PIPEDA: Overlapping Consent Requirements
For commercial electronic messages (emails, texts, notifications), you face a dual consent framework:
- PIPEDA requires consent to collect and use the email address
- CASL requires separate, specific consent to send commercial electronic messages
These are not the same consent. A customer who gives you their email address for order confirmations has not necessarily consented to receive your promotional newsletter.
Best practice: Maintain separate opt-in mechanisms and records for PIPEDA data collection and CASL commercial messaging. See our CASL compliance guide for detailed CASL consent requirements.
Building a Compliant Consent Architecture
Here is a practical framework for SMBs:
For Your Website
- Cookie consent banner — separate consent for analytics, marketing, and functional cookies
- Sign-up forms — clear statement of purpose; separate checkbox for marketing emails (not pre-ticked)
- Privacy policy link — visible at every consent point
- Preference centre — allow users to update their preferences at any time
For Your Business Operations
- New customer intake — document what information is collected and why
- Third-party sharing — list all vendors in your privacy policy; get express consent before sharing for their marketing
- Staff monitoring — inform employees in writing what workplace monitoring occurs
- Sensitive data — use written consent forms with explicit descriptions
Record-Keeping
- Log the date, method, and version of consent collected
- Store consent records for the duration of the relationship plus a reasonable period after
- Be prepared to demonstrate valid consent if challenged by the OPC
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Frequently Asked Questions
Q: Can I use a pre-ticked checkbox for marketing consent? A: No. The OPC has been clear that pre-ticked boxes do not constitute valid express consent. Users must take an affirmative action to opt in.
Q: Does consent expire? A: PIPEDA doesn't set a specific expiry for consent, but consent should remain valid only for as long as the purpose remains relevant. For marketing consent, re-engaging inactive subscribers after a year or more is good practice.
Q: What if a customer gives me their business card at a trade show? A: Exchanging business cards creates implied consent to contact that person for business purposes related to the context of the exchange. It does not create consent to add them to your email marketing list without further permission.
Q: Can I process personal information without consent in some circumstances? A: Yes. PIPEDA provides exceptions for law enforcement, national security, journalistic purposes, and situations where seeking consent would compromise an investigation. For business purposes, exceptions are narrow and should not be relied upon routinely.
Q: How do I handle consent when I acquire another business's customer list? A: You cannot simply inherit consent. The original consents given to the acquired business may not extend to your uses of the data. You should review what customers consented to and obtain fresh consent for any new purposes.
Automate Your Consent Management
Managing consent manually across websites, CRM systems, and marketing platforms is a compliance risk. Records get lost, withdrawals are missed, and consent scopes become unclear over time.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Related reading: CASL Compliance Guide | PIPEDA Checklist 2026 | Office of the Privacy Commissioner Consent Guidance
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
PIPEDA Penalties and Fines 2026: What Canadian Businesses Actually Risk
What PIPEDA non-compliance actually costs in 2026: the offence provisions, how the Privacy Commissio...
What is PIPEDA? Meaning, Principles and Who Must Comply
What PIPEDA is, who it applies to, and the 10 fair information principles Canadian businesses must f...