Canadian Privacy
Part of the PIPEDA guide

PIPEDA Penalties and Fines 2026: What Canadian Businesses Actually Risk

What PIPEDA non-compliance actually costs in 2026: the offence provisions, how the Privacy Commissioner handles complaints, and the real exposure.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
11 min read
PIPEDA Fines
PIPEDA Penalties
OPC Enforcement
Privacy Compliance
Canadian Law

One of the most common misconceptions among Canadian business owners is that PIPEDA is a "soft" law — one with no real consequences for non-compliance. Here is what your business actually risks.

Last updated: April 2026

The Real Cost of PIPEDA Non-Compliance

Criminal Penalties Under PIPEDA

The Personal Information Protection and Electronic Documents Act makes it an offence to knowingly contravene certain provisions or to obstruct the Commissioner, punishable by fines of up to $10,000 on summary conviction or $100,000 on indictment (s. 28):

OffenceMaximum Penalty
Failing to keep required records of breaches of security safeguards (s. 10.3(1))$100,000
Retaliating against an employee who raises a privacy concern (s. 27.1(1))$100,000
Obstructing a Privacy Commissioner investigation$100,000
Destroying records subject to an access request (s. 8(8))$100,000
Failing to notify the OPC of a qualifying data breach (s. 10.1)$100,000

Regulatory Consequences Beyond Fines

Fines are not the only consequence of PIPEDA non-compliance. Other consequences — often more damaging — include:

1. Published OPC Findings When the OPC investigates a complaint and finds non-compliance, it publishes a Summary of Findings on its website — including your organisation's name and the nature of the breach. These findings are indexed by search engines and can surface for years.

2. Compliance Orders The OPC can apply to the Federal Court for orders requiring organisations to correct practices. Court orders are public records.

3. Private Right of Action PIPEDA allows individuals to bring private civil lawsuits after an OPC investigation. Canadian courts have awarded damages in privacy cases — the Privacy Act lawsuit culture that defined US law is increasingly arriving in Canada.

4. Class Action Exposure Data breaches can trigger class action litigation in Canada, with legal costs that may exceed any regulatory fine.

Recent OPC Enforcement — Notable Cases

Tim Hortons (2022 — Ongoing Consequences)

The OPC found Tim Hortons' mobile app tracked customer location data every few minutes, even when the app was not in use — without adequate consent. The ruling required changes to the app and generated massive media coverage. The reputational cost far exceeded any regulatory penalty.

Facebook / Meta (Multiple Investigations)

Facebook faced multiple OPC investigations for sharing user data with Cambridge Analytica and for inadequate consent mechanisms. The investigations resulted in Federal Court applications and required significant platform changes across Canadian operations.

Desjardins Group (2019)

Canada's largest credit union suffered a breach affecting 4.2 million members' personal financial data. While this predates mandatory breach reporting improvements, it resulted in a $201 million class action settlement — one of the largest in Canadian history.

What Triggers an OPC Investigation?

The OPC can investigate based on:

  1. Individual complaints — Anyone who has been denied an access request or believes their information was misused can file a complaint at priv.gc.ca
  2. Mandatory breach reports — When you report a breach involving real risk of significant harm, the OPC may open a proactive investigation
  3. Commissioner-initiated investigations — The OPC can investigate on its own initiative when it identifies patterns or systemic issues
  4. Media reports and referrals — High-profile news stories about data handling frequently trigger OPC interest

Provincial Enforcement: Even Stricter Regimes

If you operate in Quebec, Alberta, or British Columbia, provincial regulators have independent enforcement powers:

Quebec — Commission d'accès à l'information (CAI) Quebec's Law 25 introduced penal fines of up to $25 million or 4% of worldwide turnover (whichever is greater), and monetary administrative penalties of up to $10 million or 2% of worldwide turnover, for enterprises.

Alberta — Office of the Information and Privacy Commissioner Alberta's PIPA gives the Commissioner power to issue orders (s. 52). Offences under the Act are punishable by fines of up to $100,000 for organizations (s. 59), through prosecution rather than administrative penalties.

British Columbia — Office of the Information and Privacy Commissioner BC's PIPA similarly empowers the Commissioner to investigate, issue orders, and publish findings.

Common PIPEDA Compliance Gaps (and How to Avoid Them)

1. Inadequate Consent

  • Fix: Implement clear, unambiguous consent mechanisms. Pre-ticked boxes don't count for express consent.

2. Excessive Data Collection

  • Fix: Conduct a data minimisation audit. Collect only what you need for a specific, documented purpose.

3. Inadequate Security Safeguards

  • Fix: Encrypt sensitive data at rest and in transit. Implement access controls and regular security testing.

4. Improper Third-Party Sharing

  • Fix: Review all vendor contracts to ensure personal information is protected under the same standards as your own.

5. Failure to Honour Access Requests

  • Fix: Create a documented process for responding to access requests within 30 days.

How to Reduce Your Liability Right Now

You don't need to be perfectly compliant overnight. Start by making sure your organisation:

  • Have a documented privacy programme (even a basic one)
  • Are actively working toward compliance
  • Respond quickly and cooperatively when issues arise
  • Notify affected individuals promptly following a breach

Priority actions for SMBs:

  1. Appoint a Privacy Officer (even if part-time)
  2. Publish a privacy policy on your website
  3. Audit your consent mechanisms
  4. Implement breach detection and notification procedures
  5. Train staff on the basics annually

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Frequently Asked Questions

Q: Has the OPC actually fined businesses under PIPEDA? A: The OPC itself doesn't issue fines — it investigates and makes recommendations. Fines require prosecution under the criminal provisions of PIPEDA, which is rare. However, the OPC can seek Federal Court orders, and in Quebec the CAI can impose monetary administrative penalties directly.

Q: What's the difference between a finding and a fine? A: An OPC "finding" is a published report concluding whether an organisation violated PIPEDA. It doesn't come with a monetary penalty but causes significant reputational harm. Fines require criminal prosecution or, in Quebec, CAI administrative action.

Q: Are there safe harbour provisions if I have a privacy programme? A: PIPEDA does not have formal safe harbour provisions, but demonstrating reasonable security measures and good-faith compliance efforts substantially reduces your risk of adverse enforcement outcomes.

Q: Do I need to report every data breach? A: No — only breaches that pose a "real risk of significant harm" to individuals. This is assessed based on the sensitivity of the data, the number of people affected, and the likelihood the information will be misused. When in doubt, report.

Q: How much does it cost to become PIPEDA compliant? A: It depends on the size of your organisation, the sensitivity of the personal information you hold, and how much of the work you do in-house.


Protect Your Business Before It's Too Late

The question is not whether enforcement will affect Canadian SMBs — it's which ones are unprepared.

Get your free compliance check — about two minutes, no account needed.

Further reading: PIPEDA Compliance Checklist 2026 | Office of the Privacy Commissioner

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.