Canadian Privacy

Provincial Privacy Laws Comparison: PIPEDA, Law 25, Alberta PIPA, BC PIPA

Complete comparison of Canadian provincial privacy laws. PIPEDA vs Quebec Law 25 vs Alberta PIPA vs BC PIPA for multi-provincial businesses.

Canada Compliance AI•
January 21, 2026
Updated September 12, 2026
13 min read
PIPEDA
Law 25
Alberta PIPA
BC PIPA
provincial privacy laws
multi-jurisdictional compliance

Canadian businesses navigating privacy compliance face a complex landscape: federal PIPEDA, Quebec's Law 25, Alberta's PIPA, BC's PIPA, and sector-specific provincial laws. Understanding which law applies when—and how they differ—is essential for compliance.

This comprehensive guide compares Canada's major privacy laws to help businesses operating across provinces understand their obligations.

Canada's Fragmented Privacy Framework

Why Multiple Laws?

Constitutional Division:

  • Federal government jurisdiction over certain industries
  • Provincial jurisdiction over most private sector businesses
  • Result: Overlapping and sometimes competing frameworks

Federal Jurisdiction (PIPEDA applies):

  • Banks and financial institutions
  • Airlines and interprovincial transportation
  • Telecommunications
  • Businesses without provincial substantially similar law

Provincial Jurisdiction:

  • Most private sector businesses in provinces with own laws
  • Quebec: Law 25 applies to all Quebec private sector
  • Alberta: PIPA applies to Alberta private sector
  • BC: PIPA applies to BC private sector

Federal PIPEDA: The Baseline

Overview

Full Name: Personal Information Protection and Electronic Documents Act
Enacted: 2000 (fully in force 2004)
Applies To: Federally-regulated businesses + provinces without substantially similar law
Enforcement: Privacy Commissioner of Canada
Penalties: Fines up to $100,000 for certain offences (s. 28)

10 Fair Information Principles

  1. Accountability: Organizations responsible for personal information
  2. Identifying Purposes: Purposes identified before/at collection
  3. Consent: Knowledge and consent required
  4. Limiting Collection: Collect only necessary information
  5. Limiting Use, Disclosure, Retention: Use only for identified purposes
  6. Accuracy: Personal information must be accurate
  7. Safeguards: Security appropriate to sensitivity
  8. Openness: Privacy policies and practices accessible
  9. Individual Access: Right to access personal information
  10. Challenging Compliance: Complaint procedures available

Key Requirements

Consent Management:

  • Express consent for sensitive information
  • Implied consent for appropriate circumstances
  • Withdrawal must be possible

Security Safeguards:

  • Physical, organizational, technological measures
  • Appropriate to information sensitivity

Breach Notification:

  • Report to Privacy Commissioner if "real risk of significant harm"
  • Notify affected individuals
  • Keep breach records

Individual Rights:

  • Access personal information (30-day response)
  • Request corrections
  • Challenge compliance

Penalties:

  • Privacy Commissioner recommendations
  • Federal Court orders
  • Fines up to $100,000

When PIPEDA Applies

Scenario 1: Federal jurisdiction business (bank, airline, telecom)

  • PIPEDA applies regardless of province

Scenario 2: Business in province without substantially similar law

  • Ontario, Saskatchewan, Manitoba, Atlantic provinces
  • PIPEDA applies to private sector

Scenario 3: Interprovincial/international transactions

  • Even in provinces with own laws, PIPEDA may apply to cross-border activities

Quebec Law 25: Canada's Most Comprehensive

Overview

Full Name: Act respecting the protection of personal information in the private sector (as amended by Law 25)
Fully In Force: September 2024
Applies To: All Quebec private sector organizations + organizations with Quebec residents' data
Enforcement: Commission d'accès à l'information (CAI)
Penalties: Up to $25 million or 4% of global revenue

Key Enhancements Over PIPEDA

1. Mandatory Privacy Officer

  • Must designate Privacy Officer (can be highest authority)
  • Publish name/title and contact information
  • Easily accessible on website

2. Privacy Impact Assessments (PIAs) Required before:

  • Acquiring, developing, or overhauling information systems or electronic service delivery systems (s. 3.3)

3. Transfer Risk Assessments (TRAs) Required before communicating personal information outside Quebec:

  • Assess destination jurisdiction protections
  • Document safeguards
  • Evaluate risks
  • Put the communication in a written agreement that takes the assessment results into account (s. 17)

4. Enhanced Consent

  • Separate consent for different purposes
  • Special requirements for minors under 14
  • Easy withdrawal mechanisms

5. Breach Notification

  • Notify the CAI promptly where a confidentiality incident presents a risk of serious injury (no fixed number of hours)
  • Notify affected individuals as well
  • Specific information required in notification

6. Data Subject Rights

  • Explicit right to data portability
  • Right to request deletion (with exceptions)
  • Enhanced transparency rights

7. Automated Decision-Making

  • Notice when a decision is based exclusively on automated processing (s. 12.1)
  • On request, the reasons and principal factors and parameters that led to the decision
  • Opportunity to submit observations to a staff member in a position to review the decision

8. Penalties

  • Administrative monetary penalties (AMPs): up to $10 million or 2% of worldwide turnover, whichever is greater (s. 90.12)
  • Penal fines: up to $25 million or 4% of worldwide turnover, whichever is greater (s. 91), doubled for subsequent offences (s. 92.1)
  • Much higher than PIPEDA's $100,000

Law 25 vs PIPEDA Comparison

FeaturePIPEDALaw 25
Privacy OfficerMust designate accountable individual(s) (Schedule 1, Principle 4.1)Mandatory, publicly disclosed
PIAsBest practiceMandatory for new systems
TRAsNot explicitMandatory for cross-border
Breach Timeline"As soon as feasible""Promptly" to CAI
Data PortabilityNot explicitExplicit right
Deletion RightsLimitedExplicit right
PenaltiesUp to $100KUp to $25M or 4% revenue
Automated DecisionsBasic principlesExplicit transparency

When Law 25 Applies

Scenario 1: Business located in Quebec

  • Law 25 applies to Quebec operations

Scenario 2: Business outside Quebec with Quebec customers

  • Law 25 applies to Quebec residents' personal information
  • Extraterritorial application

Example: Toronto SaaS company with Quebec customers must comply with Law 25 for those customers' data.

Alberta PIPA: Substantially Similar to PIPEDA

Overview

Full Name: Personal Information Protection Act (Alberta)
In Force: January 1, 2004 (s. 75)
Applies To: Alberta private sector organizations
Deemed: Substantially similar to PIPEDA
Enforcement: Office of the Information and Privacy Commissioner of Alberta
Penalties: Court orders, compliance orders

Key Provisions

Collection, Use, Disclosure:

  • Similar consent requirements to PIPEDA
  • Reasonable purposes framework
  • Individual access rights

Safeguards:

  • Security appropriate to sensitivity
  • Administrative, technical, physical measures

Individual Rights:

  • Access to personal information
  • Request corrections
  • Withdraw consent (subject to legal/contractual limits)

Breach Notification:

  • Real risk of significant harm threshold (same as PIPEDA)
  • Notify the Commissioner without unreasonable delay (s. 34.1); the Commissioner may require notification of affected individuals (s. 37.1)

Differences from PIPEDA

Provincial Enforcement:

  • Alberta Privacy Commissioner (not federal)
  • Provincial complaint process
  • Provincial court jurisdiction

Some Procedural Variations:

  • Different investigation timelines
  • Different order/recommendation structure
  • Provincial appeal process

Employee Information:

  • Some specific provisions for employee data
  • Workplace privacy considerations

When Alberta PIPA Applies

Scenario 1: Business operates primarily in Alberta

  • PIPA applies to Alberta operations

Scenario 2: Cross-provincial operations

  • PIPA for Alberta activities
  • PIPEDA may apply to interprovincial/international aspects

British Columbia PIPA: Similar to Alberta

Overview

Full Name: Personal Information Protection Act (British Columbia)
In Force: January 1, 2004 (s. 60)
Applies To: BC private sector organizations
Deemed: Substantially similar to PIPEDA
Enforcement: Office of the Information and Privacy Commissioner for British Columbia
Penalties: Court orders, compliance orders

Key Provisions

Core Principles:

  • Mirroring PIPEDA's fair information principles
  • Consent-based framework
  • Individual access rights
  • Security safeguards

Notable BC Provisions:

  • Employee personal information rules
  • No general mandatory breach notification provision in the Act

Differences from Alberta PIPA

Minor Variations:

  • Some procedural differences
  • Slightly different definitions
  • Different Commissioner practices
  • Provincial enforcement approach

Largely Aligned: Both Alberta and BC PIPA substantially similar to PIPEDA and to each other.

When BC PIPA Applies

Scenario 1: Business operates in BC

  • BC PIPA applies to BC operations

Scenario 2: Interprovincial operations

  • BC PIPA for BC activities
  • PIPEDA may apply to cross-border aspects

Other Provincial Considerations

Ontario: Sector-Specific Laws

No General Private Sector Law:

  • PIPEDA applies to most Ontario private sector
  • Sector-specific laws exist:

PHIPA (Personal Health Information Protection Act):

  • Healthcare providers ("health information custodians")
  • Patient personal health information
  • Enhanced protections for health data
  • Applies instead of PIPEDA for health custodians

Other Sectors:

  • MFIPPA: Municipal public sector
  • FIPPA: Provincial public sector

Other Provinces

Saskatchewan, Manitoba, New Brunswick, Nova Scotia, PEI, Newfoundland:

  • No substantially similar private sector laws
  • PIPEDA applies to private sector

Nunavut, Northwest Territories, Yukon:

  • PIPEDA applies to private sector

Multi-Provincial Compliance Strategy

Determining Which Laws Apply

Step 1: Identify Business Locations Where do you operate? Where are employees located?

Step 2: Identify Customer Locations Where are customers located? (Law 25 has extraterritorial reach)

Step 3: Assess Industry Federally regulated? (Banks, telecoms, airlines → PIPEDA)

Step 4: Map Applicable Laws

  • Federal business → PIPEDA
  • Quebec operations or customers → Law 25
  • Alberta operations → PIPA (Alberta)
  • BC operations → PIPA (BC)
  • Ontario, other provinces → PIPEDA (unless sector-specific)

Example 1: Toronto E-Commerce Company

  • Ontario location → PIPEDA baseline
  • Customers across Canada → Law 25 for Quebec customers
  • Compliance: PIPEDA + Law 25 for Quebec customers

Example 2: Montreal SaaS Company

  • Quebec location → Law 25
  • National customer base → Law 25 for all (strictest standard)
  • Interprovincial aspects → PIPEDA may also apply
  • Compliance: Law 25 (covers PIPEDA requirements)

Example 3: Calgary Consulting Firm

  • Alberta location → Alberta PIPA
  • Western Canada clients → AB PIPA, BC PIPA (if BC clients)
  • Compliance: Alberta PIPA + BC PIPA for BC clients

Compliance with Strictest Standard Approach

Most Efficient Strategy: Comply with most comprehensive law (Law 25), ensuring coverage of all other requirements.

Why Law 25 as Standard:

  • Most comprehensive Canadian privacy law
  • Extraterritorial application
  • Covers most PIPEDA requirements
  • Exceeds Alberta/BC PIPA in several areas

What This Means:

  • Implement Law 25 requirements organization-wide
  • Mandatory Privacy Officer
  • PIAs for new systems
  • TRAs for cross-border transfers
  • Prompt CAI breach notification capability
  • Enhanced consent management
  • Data portability and deletion processes

Result: Compliant with Law 25 = largely compliant with PIPEDA and provincial PIPAs.

Documentation Requirements

Compliance Matrix: Document which laws apply to which parts of your business:

  • Business unit/department
  • Geographic scope
  • Applicable laws
  • Compliance status
  • Responsible person

Policy Alignment:

  • Single privacy policy covering all requirements
  • Jurisdiction-specific addendums if needed
  • Clear statement of applicable laws

Training:

  • Educate staff on multi-jurisdictional requirements
  • Department-specific training based on applicable laws
  • Regular updates as laws change

When to Seek Legal Advice

Complex Scenarios:

  • Operating in multiple provinces with significant presence
  • Federally-regulated with provincial operations
  • Cross-border data transfers
  • M&A involving multi-jurisdictional privacy compliance
  • Enforcement action or complaint

Cost-Benefit: Weigh the cost of legal review against potential Law 25 penal fines (up to $25M or 4% of worldwide turnover)

Provincial Law Changes and Trends

Harmonization Unlikely

Current Reality:

  • Quebec strengthening privacy protections (Law 25)
  • Federal reform (Bill C-36) at second reading; not yet law
  • Provinces unlikely to weaken existing protections
  • Trend toward stronger, not weaker, privacy laws

Bill C-27 (Federal CPPA) and Bill C-36

Bill C-27, which would have repealed Part 1 of PIPEDA and enacted the CPPA, died on the Order Paper when Parliament was prorogued in January 2025. It never became law, and PIPEDA remains in force.

Federal privacy reform was re-introduced as Bill C-36, introduced and read a first time in the House of Commons on June 15, 2026, and currently at second reading. Its content could change before passage, and it is not yet law (LEGISinfo).

Monitoring Changes

Stay Updated:

  • Subscribe to Privacy Commissioner updates (federal and provincial)
  • Monitor legislative developments
  • Join industry associations
  • Engage privacy law firms or consultants
  • Attend privacy conferences

Practical Compliance Recommendations

For Single-Province Businesses

Quebec Only:

  • Implement Law 25 fully
  • Mandatory Privacy Officer, PIAs, TRAs
  • Prompt CAI breach notification prep

Alberta Only:

  • Implement Alberta PIPA
  • Monitor federal privacy reform (Bill C-36)
  • Consider voluntary Law 25 elements for future-proofing

BC Only:

  • Implement BC PIPA
  • Monitor federal privacy reform (Bill C-36)
  • Consider voluntary Law 25 elements

Ontario, Other Provinces:

  • Implement PIPEDA
  • Monitor Bill C-36
  • Consider voluntary Law 25 elements (especially if growth into Quebec planned)

For Multi-Provincial Businesses

Strategy:

  1. Implement Law 25 as baseline
  2. Document compliance with all applicable laws
  3. Train staff on multi-jurisdictional requirements
  4. Monitor all relevant legislative changes
  5. Annual compliance audit covering all jurisdictions

Cost-Efficiency: Single compliance program based on strictest standard (Law 25) more efficient than maintaining multiple separate programs.

For Growing Businesses

Future-Proof Approach:

  • Even if not in Quebec now, implement Law 25 standards
  • Easier to expand into new provinces
  • Demonstrates strong privacy commitment
  • Competitive advantage for enterprise sales

Comparison Summary Table

FeaturePIPEDAQuebec Law 25AB PIPABC PIPA
JurisdictionFederal businesses + provinces without lawQuebec private sectorAlberta private sectorBC private sector
Privacy OfficerMust designate accountable individual(s) (Schedule 1, Principle 4.1)Mandatory (published)—Must designate responsible individual(s) (s. 4(3))
PIAsBest practiceMandatoryNot explicitNot explicit
TRAsNot explicitMandatory for cross-borderNot explicitNot explicit
Consent FrameworkExpress/impliedEnhanced, granularExpress/impliedExpress/implied
Breach NotificationReal risk of significant harmRisk of serious injury; notify CAI promptlyReal risk (s. 34.1)No general mandatory provision
PenaltiesUp to $100KUp to $25M or 4%Court ordersCourt orders
Data PortabilityNot explicitExplicit rightNot explicitNot explicit
Deletion RightsAccess + correctionExplicit disposal rightAccess + correctionAccess + correction
Automated DecisionsBasic principlesExplicit transparencyBasicBasic
EnforcementPrivacy Commissioner of CanadaCommission d'accès à l'information (CAI)AB Privacy CommissionerBC Privacy Commissioner

Conclusion

Canada's privacy landscape is complex, with federal PIPEDA and multiple provincial laws creating overlapping requirements. Quebec's Law 25 stands as the most comprehensive Canadian privacy law, with mandatory Privacy Officers, PIAs, TRAs, and penalties up to $25 million or 4% of revenue.

Key Takeaways:

  • Multiple laws may apply to single business
  • Law 25 provides most comprehensive framework
  • Compliance with strictest standard most efficient
  • Professional advice valuable for complex scenarios

Recommended Approach:

  1. Map which laws apply to your business
  2. Implement Law 25 standards organization-wide
  3. Document multi-jurisdictional compliance
  4. Monitor legislative developments
  5. Update as regulations evolve

The investment in comprehensive privacy compliance—particularly meeting Law 25's enhanced standards—positions businesses for success across all Canadian jurisdictions while preparing for future regulatory enhancements.

Related reading: Ontario Privacy Compliance | AODA Website Compliance 2026


Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.