Canadian Privacy

What Personal Information Does PIPEDA Protect? Complete Guide

What counts as personal information under PIPEDA, what does not, how sensitive information is treated and what it means for your data inventory.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
10 min read
PIPEDA Personal Information
What is Personal Information
PIPEDA Definition
Canadian Privacy Law
Data Protection Canada

Understanding what qualifies as "personal information" under PIPEDA is the foundation of Canadian privacy compliance. Get this wrong and you'll either over-collect (creating unnecessary risk) or under-protect (creating legal exposure). This guide covers the full scope of PIPEDA's personal information definition with practical examples for Canadian businesses.

Last updated: April 2026

PIPEDA's Definition of Personal Information

Under PIPEDA, personal information means "information about an identifiable individual." This definition is intentionally broad. Courts and the Office of the Privacy Commissioner (OPC) have interpreted it expansively to protect individual privacy in the digital age.

The key elements are:

  1. Information — any data, fact, opinion, or observation
  2. About — relates to, characterises, or is connected to a person
  3. An identifiable individual — could be used to identify a specific person, alone or in combination

The last element is crucial: information doesn't need to include a name to be personal information. If it can be linked back to a specific individual, it qualifies.

What Counts as Personal Information

Directly Identifying Information

The most obvious category:

  • Full name
  • Home address
  • Email address (personal)
  • Phone number
  • Date of birth
  • Social Insurance Number (SIN)
  • Passport or driver's licence number
  • Financial account numbers

Less Obvious Personal Information

PIPEDA also covers:

  • IP addresses — the OPC's Interpretation Bulletin: Personal Information states an IP address can be considered personal information if it can be associated with an identifiable individual
  • Device identifiers — phone IMEI numbers, browser fingerprints
  • Location data — GPS coordinates, geolocation history
  • Biometric data — fingerprints, facial recognition data, voiceprints
  • Photos and videos — images that identify an individual
  • Purchase history — transaction records tied to a person
  • Web browsing history — especially when tied to a user account
  • Preferences and interests — user profiles, behavioural data
  • Communications — emails, messages (content and metadata)

Health and Medical Information

Health information receives heightened protection under PIPEDA because of its sensitivity:

  • Medical diagnoses and treatment records
  • Prescription history
  • Mental health records
  • Disability information
  • Genetic data
  • Health insurance information

For healthcare organisations in provinces such as Alberta (Health Information Act) and Ontario (PHIPA), separate health information legislation adds additional requirements beyond PIPEDA.

Financial Information

Financial personal information includes:

  • Bank account details
  • Credit card numbers
  • Credit scores and credit reports
  • Income and salary information
  • Tax returns and financial statements (of individuals)
  • Debt history and bankruptcy records

Employee Information

Employment information about individuals is personal information:

  • Job application materials (resume, cover letter)
  • Performance reviews
  • Disciplinary records
  • Salary and compensation
  • Leave records
  • Benefits information
  • Workplace medical accommodations

Opinions and Beliefs

PIPEDA's definition does not list categories, but the OPC's Interpretation Bulletin: Personal Information notes that an individual's views or opinions about an employee (such as performance appraisals) may constitute that employee's personal information — meaning that what someone else says about a person can also be personal information.

This category includes:

  • Customer reviews that identify an individual
  • Reference letters
  • Supervisory assessments
  • Background check results

What Is NOT Personal Information Under PIPEDA

Business Contact Information

PIPEDA contains an important exclusion: business contact information used solely for business communications is not personal information. This includes:

  • A person's name, title, business address, telephone number, and email at their employer

Critical caveat: This exclusion applies only when the information is used to contact the person in their business capacity. If you use a person's business email to send personal communications or build marketing profiles, it reverts to being personal information.

Aggregated and Anonymised Data

Truly anonymised information — where no individual can be identified from the data or by combining it with other available information — is not personal information under PIPEDA.

However, the OPC and courts have become increasingly skeptical of "anonymisation" claims in the era of big data. Re-identification risk is real, and the bar for true anonymisation is high.

The aggregation problem: Individual data points that seem anonymous can become identifiable when combined. A dataset showing age + postal code + occupation may allow re-identification even without a name.

Deceased Individuals

PIPEDA's definition of personal information is not limited to living individuals. For example, section 7(3)(h) allows disclosure without consent of information once the earlier of 100 years after the record was created or 20 years after the individual's death has passed (PIPEDA).

Sensitive Personal Information

While PIPEDA protects all personal information, some categories are treated as sensitive and require heightened protection:

  • Medical/health information
  • Financial information (especially SINs and account details)
  • Ethnic or racial origin
  • Political opinions
  • Religious or philosophical beliefs
  • Sexual orientation or gender identity
  • Criminal history or proceedings
  • Biometric data

For sensitive personal information, PIPEDA generally requires express consent rather than implied consent, and stricter security safeguards.

The Contextual Nature of Personal Information

Context matters enormously in determining whether information is personal:

Example 1 — The same data, different contexts:

  • "John Smith" in a public phonebook: arguably not personal information in the PIPEDA sense for ordinary contact
  • "John Smith" in a medical record: clearly personal information

Example 2 — Combination creates identifiability:

  • "Male, 35, lives in Kelowna, works in viticulture, drives a Ford F-150" — none of these individually might identify someone, but combined they might identify a specific individual

Example 3 — Business vs. personal:

Practical Implications for Your Data Inventory

When conducting a data inventory (required for a proper PIPEDA compliance programme), categorise information into:

CategoryPIPEDA Applies?Sensitivity Level
Customer names + emailsYesStandard
IP addresses and browsing dataYesStandard–High
Health/medical informationYesHigh
Financial records (SINs, banking)YesHigh
Employee HR recordsYesStandard–High
Business contact info (used for business comms)No (exclusion)N/A
Truly anonymised analyticsNoN/A
Photos identifying individualsYesStandard

Common Mistakes Canadian Businesses Make

Mistake 1: Assuming business emails are always excluded The business contact exclusion is narrow. Using a business email for marketing or building customer profiles removes the exclusion.

Mistake 2: Treating aggregated data as completely safe Aggregated analytics dashboards may still contain re-identifiable data. Review carefully.

Mistake 3: Ignoring metadata The content of an email may not be personal information, but the metadata (who sent it, when, to whom) often is.

Mistake 4: Thinking old data is not personal information PIPEDA's definition doesn't expire. Historical personal information in old files remains subject to PIPEDA obligations including retention limits.

Mistake 5: Overlooking employee monitoring data Keystroke logs, website access records, and security camera footage of employees are all personal information under PIPEDA (and PIPA in Alberta/BC).

Frequently Asked Questions

Q: Is a customer's first name alone personal information? A: A first name alone is typically not enough to identify an individual and wouldn't qualify as personal information on its own. But in combination with other data (company, city, role), it may become identifiable.

Q: Are testimonials and reviews personal information? A: If a testimonial includes identifying information (name, photo, company), it's personal information. You should obtain consent before publishing it on your website.

Q: Do we need to protect information about deceased clients? A: PIPEDA's protections do not simply end at death (see section 7(3)(h)). Also consider provincial laws and any contractual obligations. Many businesses maintain confidentiality for deceased clients out of professional practice.

Q: Is a photo of a crowd at an event personal information? A: A crowd photo where individuals are not identifiable is generally not personal information. A close-up photo clearly showing an individual's face is personal information.


Know Your Data. Protect Your Business.

Canada Compliance AI helps Canadian businesses conduct data inventories, categorise personal information, and build PIPEDA-compliant programmes — without the complexity of doing it alone.

Start your free trial today — understand your data, control your risk.

Related reading: PIPEDA Compliance Guide | PIPEDA Consent Requirements | Data Breach Response Canada

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.