Provincial Privacy Laws Comparison: PIPEDA, Law 25, Alberta PIPA, BC PIPA
Complete comparison of Canadian provincial privacy laws. PIPEDA vs Quebec Law 25 vs Alberta PIPA vs BC PIPA for multi-provincial businesses.
Canadian businesses navigating privacy compliance face a complex landscape: federal PIPEDA, Quebec's Law 25, Alberta's PIPA, BC's PIPA, and sector-specific provincial laws. Understanding which law applies when—and how they differ—is essential for compliance.
This comprehensive guide compares Canada's major privacy laws to help businesses operating across provinces understand their obligations.
Canada's Fragmented Privacy Framework
Why Multiple Laws?
Constitutional Division:
- Federal government jurisdiction over certain industries
- Provincial jurisdiction over most private sector businesses
- Result: Overlapping and sometimes competing frameworks
Federal Jurisdiction (PIPEDA applies):
- Banks and financial institutions
- Airlines and interprovincial transportation
- Telecommunications
- Businesses without provincial substantially similar law
Provincial Jurisdiction:
- Most private sector businesses in provinces with own laws
- Quebec: Law 25 applies to all Quebec private sector
- Alberta: PIPA applies to Alberta private sector
- BC: PIPA applies to BC private sector
Federal PIPEDA: The Baseline
Overview
Full Name: Personal Information Protection and Electronic Documents Act
Enacted: 2000 (fully in force 2004)
Applies To: Federally-regulated businesses + provinces without substantially similar law
Enforcement: Privacy Commissioner of Canada
Penalties: Fines up to $100,000 for certain offences (s. 28)
10 Fair Information Principles
- Accountability: Organizations responsible for personal information
- Identifying Purposes: Purposes identified before/at collection
- Consent: Knowledge and consent required
- Limiting Collection: Collect only necessary information
- Limiting Use, Disclosure, Retention: Use only for identified purposes
- Accuracy: Personal information must be accurate
- Safeguards: Security appropriate to sensitivity
- Openness: Privacy policies and practices accessible
- Individual Access: Right to access personal information
- Challenging Compliance: Complaint procedures available
Key Requirements
Consent Management:
- Express consent for sensitive information
- Implied consent for appropriate circumstances
- Withdrawal must be possible
Security Safeguards:
- Physical, organizational, technological measures
- Appropriate to information sensitivity
Breach Notification:
- Report to Privacy Commissioner if "real risk of significant harm"
- Notify affected individuals
- Keep breach records
Individual Rights:
- Access personal information (30-day response)
- Request corrections
- Challenge compliance
Penalties:
- Privacy Commissioner recommendations
- Federal Court orders
- Fines up to $100,000
When PIPEDA Applies
Scenario 1: Federal jurisdiction business (bank, airline, telecom)
- PIPEDA applies regardless of province
Scenario 2: Business in province without substantially similar law
- Ontario, Saskatchewan, Manitoba, Atlantic provinces
- PIPEDA applies to private sector
Scenario 3: Interprovincial/international transactions
- Even in provinces with own laws, PIPEDA may apply to cross-border activities
Quebec Law 25: Canada's Most Comprehensive
Overview
Full Name: Act respecting the protection of personal information in the private sector (as amended by Law 25)
Fully In Force: September 2024
Applies To: All Quebec private sector organizations + organizations with Quebec residents' data
Enforcement: Commission d'accès à l'information (CAI)
Penalties: Up to $25 million or 4% of global revenue
Key Enhancements Over PIPEDA
1. Mandatory Privacy Officer
- Must designate Privacy Officer (can be highest authority)
- Publish name/title and contact information
- Easily accessible on website
2. Privacy Impact Assessments (PIAs) Required before:
- Acquiring, developing, or overhauling information systems or electronic service delivery systems (s. 3.3)
3. Transfer Risk Assessments (TRAs) Required before communicating personal information outside Quebec:
- Assess destination jurisdiction protections
- Document safeguards
- Evaluate risks
- Put the communication in a written agreement that takes the assessment results into account (s. 17)
4. Enhanced Consent
- Separate consent for different purposes
- Special requirements for minors under 14
- Easy withdrawal mechanisms
5. Breach Notification
- Notify the CAI promptly where a confidentiality incident presents a risk of serious injury (no fixed number of hours)
- Notify affected individuals as well
- Specific information required in notification
6. Data Subject Rights
- Explicit right to data portability
- Right to request deletion (with exceptions)
- Enhanced transparency rights
7. Automated Decision-Making
- Notice when a decision is based exclusively on automated processing (s. 12.1)
- On request, the reasons and principal factors and parameters that led to the decision
- Opportunity to submit observations to a staff member in a position to review the decision
8. Penalties
- Administrative monetary penalties (AMPs): up to $10 million or 2% of worldwide turnover, whichever is greater (s. 90.12)
- Penal fines: up to $25 million or 4% of worldwide turnover, whichever is greater (s. 91), doubled for subsequent offences (s. 92.1)
- Much higher than PIPEDA's $100,000
Law 25 vs PIPEDA Comparison
| Feature | PIPEDA | Law 25 |
|---|---|---|
| Privacy Officer | Must designate accountable individual(s) (Schedule 1, Principle 4.1) | Mandatory, publicly disclosed |
| PIAs | Best practice | Mandatory for new systems |
| TRAs | Not explicit | Mandatory for cross-border |
| Breach Timeline | "As soon as feasible" | "Promptly" to CAI |
| Data Portability | Not explicit | Explicit right |
| Deletion Rights | Limited | Explicit right |
| Penalties | Up to $100K | Up to $25M or 4% revenue |
| Automated Decisions | Basic principles | Explicit transparency |
When Law 25 Applies
Scenario 1: Business located in Quebec
- Law 25 applies to Quebec operations
Scenario 2: Business outside Quebec with Quebec customers
- Law 25 applies to Quebec residents' personal information
- Extraterritorial application
Example: Toronto SaaS company with Quebec customers must comply with Law 25 for those customers' data.
Alberta PIPA: Substantially Similar to PIPEDA
Overview
Full Name: Personal Information Protection Act (Alberta)
In Force: January 1, 2004 (s. 75)
Applies To: Alberta private sector organizations
Deemed: Substantially similar to PIPEDA
Enforcement: Office of the Information and Privacy Commissioner of Alberta
Penalties: Court orders, compliance orders
Key Provisions
Collection, Use, Disclosure:
- Similar consent requirements to PIPEDA
- Reasonable purposes framework
- Individual access rights
Safeguards:
- Security appropriate to sensitivity
- Administrative, technical, physical measures
Individual Rights:
- Access to personal information
- Request corrections
- Withdraw consent (subject to legal/contractual limits)
Breach Notification:
- Real risk of significant harm threshold (same as PIPEDA)
- Notify the Commissioner without unreasonable delay (s. 34.1); the Commissioner may require notification of affected individuals (s. 37.1)
Differences from PIPEDA
Provincial Enforcement:
- Alberta Privacy Commissioner (not federal)
- Provincial complaint process
- Provincial court jurisdiction
Some Procedural Variations:
- Different investigation timelines
- Different order/recommendation structure
- Provincial appeal process
Employee Information:
- Some specific provisions for employee data
- Workplace privacy considerations
When Alberta PIPA Applies
Scenario 1: Business operates primarily in Alberta
- PIPA applies to Alberta operations
Scenario 2: Cross-provincial operations
- PIPA for Alberta activities
- PIPEDA may apply to interprovincial/international aspects
British Columbia PIPA: Similar to Alberta
Overview
Full Name: Personal Information Protection Act (British Columbia)
In Force: January 1, 2004 (s. 60)
Applies To: BC private sector organizations
Deemed: Substantially similar to PIPEDA
Enforcement: Office of the Information and Privacy Commissioner for British Columbia
Penalties: Court orders, compliance orders
Key Provisions
Core Principles:
- Mirroring PIPEDA's fair information principles
- Consent-based framework
- Individual access rights
- Security safeguards
Notable BC Provisions:
- Employee personal information rules
- No general mandatory breach notification provision in the Act
Differences from Alberta PIPA
Minor Variations:
- Some procedural differences
- Slightly different definitions
- Different Commissioner practices
- Provincial enforcement approach
Largely Aligned: Both Alberta and BC PIPA substantially similar to PIPEDA and to each other.
When BC PIPA Applies
Scenario 1: Business operates in BC
- BC PIPA applies to BC operations
Scenario 2: Interprovincial operations
- BC PIPA for BC activities
- PIPEDA may apply to cross-border aspects
Other Provincial Considerations
Ontario: Sector-Specific Laws
No General Private Sector Law:
- PIPEDA applies to most Ontario private sector
- Sector-specific laws exist:
PHIPA (Personal Health Information Protection Act):
- Healthcare providers ("health information custodians")
- Patient personal health information
- Enhanced protections for health data
- Applies instead of PIPEDA for health custodians
Other Sectors:
- MFIPPA: Municipal public sector
- FIPPA: Provincial public sector
Other Provinces
Saskatchewan, Manitoba, New Brunswick, Nova Scotia, PEI, Newfoundland:
- No substantially similar private sector laws
- PIPEDA applies to private sector
Nunavut, Northwest Territories, Yukon:
- PIPEDA applies to private sector
Multi-Provincial Compliance Strategy
Determining Which Laws Apply
Step 1: Identify Business Locations Where do you operate? Where are employees located?
Step 2: Identify Customer Locations Where are customers located? (Law 25 has extraterritorial reach)
Step 3: Assess Industry Federally regulated? (Banks, telecoms, airlines → PIPEDA)
Step 4: Map Applicable Laws
- Federal business → PIPEDA
- Quebec operations or customers → Law 25
- Alberta operations → PIPA (Alberta)
- BC operations → PIPA (BC)
- Ontario, other provinces → PIPEDA (unless sector-specific)
Example 1: Toronto E-Commerce Company
- Ontario location → PIPEDA baseline
- Customers across Canada → Law 25 for Quebec customers
- Compliance: PIPEDA + Law 25 for Quebec customers
Example 2: Montreal SaaS Company
- Quebec location → Law 25
- National customer base → Law 25 for all (strictest standard)
- Interprovincial aspects → PIPEDA may also apply
- Compliance: Law 25 (covers PIPEDA requirements)
Example 3: Calgary Consulting Firm
- Alberta location → Alberta PIPA
- Western Canada clients → AB PIPA, BC PIPA (if BC clients)
- Compliance: Alberta PIPA + BC PIPA for BC clients
Compliance with Strictest Standard Approach
Most Efficient Strategy: Comply with most comprehensive law (Law 25), ensuring coverage of all other requirements.
Why Law 25 as Standard:
- Most comprehensive Canadian privacy law
- Extraterritorial application
- Covers most PIPEDA requirements
- Exceeds Alberta/BC PIPA in several areas
What This Means:
- Implement Law 25 requirements organization-wide
- Mandatory Privacy Officer
- PIAs for new systems
- TRAs for cross-border transfers
- Prompt CAI breach notification capability
- Enhanced consent management
- Data portability and deletion processes
Result: Compliant with Law 25 = largely compliant with PIPEDA and provincial PIPAs.
Documentation Requirements
Compliance Matrix: Document which laws apply to which parts of your business:
- Business unit/department
- Geographic scope
- Applicable laws
- Compliance status
- Responsible person
Policy Alignment:
- Single privacy policy covering all requirements
- Jurisdiction-specific addendums if needed
- Clear statement of applicable laws
Training:
- Educate staff on multi-jurisdictional requirements
- Department-specific training based on applicable laws
- Regular updates as laws change
When to Seek Legal Advice
Complex Scenarios:
- Operating in multiple provinces with significant presence
- Federally-regulated with provincial operations
- Cross-border data transfers
- M&A involving multi-jurisdictional privacy compliance
- Enforcement action or complaint
Cost-Benefit: Weigh the cost of legal review against potential Law 25 penal fines (up to $25M or 4% of worldwide turnover)
Provincial Law Changes and Trends
Harmonization Unlikely
Current Reality:
- Quebec strengthening privacy protections (Law 25)
- Federal reform (Bill C-36) at second reading; not yet law
- Provinces unlikely to weaken existing protections
- Trend toward stronger, not weaker, privacy laws
Bill C-27 (Federal CPPA) and Bill C-36
Bill C-27, which would have repealed Part 1 of PIPEDA and enacted the CPPA, died on the Order Paper when Parliament was prorogued in January 2025. It never became law, and PIPEDA remains in force.
Federal privacy reform was re-introduced as Bill C-36, introduced and read a first time in the House of Commons on June 15, 2026, and currently at second reading. Its content could change before passage, and it is not yet law (LEGISinfo).
Monitoring Changes
Stay Updated:
- Subscribe to Privacy Commissioner updates (federal and provincial)
- Monitor legislative developments
- Join industry associations
- Engage privacy law firms or consultants
- Attend privacy conferences
Practical Compliance Recommendations
For Single-Province Businesses
Quebec Only:
- Implement Law 25 fully
- Mandatory Privacy Officer, PIAs, TRAs
- Prompt CAI breach notification prep
Alberta Only:
- Implement Alberta PIPA
- Monitor federal privacy reform (Bill C-36)
- Consider voluntary Law 25 elements for future-proofing
BC Only:
- Implement BC PIPA
- Monitor federal privacy reform (Bill C-36)
- Consider voluntary Law 25 elements
Ontario, Other Provinces:
- Implement PIPEDA
- Monitor Bill C-36
- Consider voluntary Law 25 elements (especially if growth into Quebec planned)
For Multi-Provincial Businesses
Strategy:
- Implement Law 25 as baseline
- Document compliance with all applicable laws
- Train staff on multi-jurisdictional requirements
- Monitor all relevant legislative changes
- Annual compliance audit covering all jurisdictions
Cost-Efficiency: Single compliance program based on strictest standard (Law 25) more efficient than maintaining multiple separate programs.
For Growing Businesses
Future-Proof Approach:
- Even if not in Quebec now, implement Law 25 standards
- Easier to expand into new provinces
- Demonstrates strong privacy commitment
- Competitive advantage for enterprise sales
Comparison Summary Table
| Feature | PIPEDA | Quebec Law 25 | AB PIPA | BC PIPA |
|---|---|---|---|---|
| Jurisdiction | Federal businesses + provinces without law | Quebec private sector | Alberta private sector | BC private sector |
| Privacy Officer | Must designate accountable individual(s) (Schedule 1, Principle 4.1) | Mandatory (published) | — | Must designate responsible individual(s) (s. 4(3)) |
| PIAs | Best practice | Mandatory | Not explicit | Not explicit |
| TRAs | Not explicit | Mandatory for cross-border | Not explicit | Not explicit |
| Consent Framework | Express/implied | Enhanced, granular | Express/implied | Express/implied |
| Breach Notification | Real risk of significant harm | Risk of serious injury; notify CAI promptly | Real risk (s. 34.1) | No general mandatory provision |
| Penalties | Up to $100K | Up to $25M or 4% | Court orders | Court orders |
| Data Portability | Not explicit | Explicit right | Not explicit | Not explicit |
| Deletion Rights | Access + correction | Explicit disposal right | Access + correction | Access + correction |
| Automated Decisions | Basic principles | Explicit transparency | Basic | Basic |
| Enforcement | Privacy Commissioner of Canada | Commission d'accès à l'information (CAI) | AB Privacy Commissioner | BC Privacy Commissioner |
Conclusion
Canada's privacy landscape is complex, with federal PIPEDA and multiple provincial laws creating overlapping requirements. Quebec's Law 25 stands as the most comprehensive Canadian privacy law, with mandatory Privacy Officers, PIAs, TRAs, and penalties up to $25 million or 4% of revenue.
Key Takeaways:
- Multiple laws may apply to single business
- Law 25 provides most comprehensive framework
- Compliance with strictest standard most efficient
- Professional advice valuable for complex scenarios
Recommended Approach:
- Map which laws apply to your business
- Implement Law 25 standards organization-wide
- Document multi-jurisdictional compliance
- Monitor legislative developments
- Update as regulations evolve
The investment in comprehensive privacy compliance—particularly meeting Law 25's enhanced standards—positions businesses for success across all Canadian jurisdictions while preparing for future regulatory enhancements.
Related reading: Ontario Privacy Compliance | AODA Website Compliance 2026
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Vendor Risk Assessment for Canadian Businesses: Managing Third-Party Privacy Compliance
Complete vendor risk assessment guide for Canadian SMBs. Third-party privacy compliance, security qu...
Canadian DPA Requirements: Data Processing Agreements for PIPEDA and Law 25 Compliance
Complete guide to Data Processing Agreements for Canadian businesses. DPA templates, requirements, a...