Provincial Compliance

Privacy Compliance for Saskatchewan and Manitoba Businesses

Privacy law in Saskatchewan and Manitoba: how PIPEDA applies, plus each province's health information law (HIPA and PHIA) and what it means for your business.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
11 min read
Saskatchewan Privacy Law
Manitoba Privacy Law
PIPEDA Prairie Provinces
PHIA Manitoba
HIPA Saskatchewan

Saskatchewan and Manitoba are often overlooked in Canadian privacy law discussions — they lack the substantially similar private-sector privacy legislation that Alberta and BC have, so federal PIPEDA applies directly. Both provinces do have health information legislation that creates sector-specific obligations. Here's the complete privacy law framework for Prairie businesses.

Last updated: April 2026

The Saskatchewan and Manitoba Privacy Landscape

Unlike Alberta (PIPA) and BC (PIPA), neither Saskatchewan nor Manitoba has enacted private-sector privacy legislation deemed substantially similar to PIPEDA. This means:

Federal PIPEDA applies to all private-sector commercial activities in both provinces.

Provincial health information legislation applies to health information custodians in each province:

  • Saskatchewan: The Health Information Protection Act (HIPA)
  • Manitoba: The Personal Health Information Act (PHIA)

Public sector legislation covers provincial government bodies but not private businesses:

  • Saskatchewan: The Freedom of Information and Protection of Privacy Act (FOIPP)
  • Manitoba: The Freedom of Information and Protection of Privacy Act (FIPPA)

For most private-sector businesses in Saskatchewan and Manitoba, the operative laws are PIPEDA (all personal information) plus health information legislation if you're a health information trustee.


PIPEDA in Saskatchewan and Manitoba

Because no substantially similar private-sector law exists, the federal OPC enforces PIPEDA for private-sector activities in both provinces. The OPC is the relevant regulator for privacy complaints from customers and business partners.

Standard PIPEDA obligations apply:

  • Designate a Privacy Officer
  • Publish a privacy policy
  • Obtain meaningful consent for data collection
  • Limit collection to what's necessary
  • Implement appropriate security safeguards
  • Respond to access requests within 30 days
  • Report qualifying breaches to the OPC and affected individuals
  • Maintain a breach register

See the PIPEDA Compliance Guide for the full framework.


Saskatchewan: The Health Information Protection Act (HIPA)

Saskatchewan's HIPA governs personal health information (PHI) held by health information trustees — organisations or individuals who hold PHI in connection with providing health services.

Who Is a Health Information Trustee Under HIPA?

  • Regulated health professionals (physicians, dentists, pharmacists, chiropractors, optometrists, nurses, etc.)
  • Hospitals and regional health authorities
  • Long-term care facilities
  • Health research organizations
  • Government ministries related to health

Note: Employers who receive health information for employment accommodation purposes are typically not trustees — they're subject to PIPEDA for that data.

Key HIPA Obligations

Collection and Consent: HIPA allows collection of PHI with or without consent in certain circumstances (for treatment, payment for treatment, health system management). For non-essential purposes (fundraising, marketing, research), express consent is required.

Individual Rights: Individuals have the right to access and request correction of their own PHI. Trustees must respond to access requests within 30 days (s. 36), extendable by up to a further 30 days in specified circumstances (s. 37) (HIPA).

Regulator: The Information and Privacy Commissioner of Saskatchewan enforces HIPA (and FOIPP for the public sector).

Healthcare Businesses in Saskatchewan

If you're a healthcare provider in Saskatchewan:

  1. HIPA is your primary law for patient health information
  2. PIPEDA covers other personal information (employee data, administrative data) not within HIPA's scope
  3. Your practice management software, clinic operations, and patient records all fall under HIPA

Manitoba: The Personal Health Information Act (PHIA)

Manitoba's PHIA governs personal health information held by trustees — defined similarly to Saskatchewan's HIPA.

Who Is a Trustee Under PHIA?

  • Regulated health professionals
  • Hospitals, personal care homes, licensed health facilities
  • Regional Health Authorities
  • Manitoba Health (provincial government)
  • Ambulance services

Key PHIA Obligations

Consent: Similar to other provincial health laws — treatment-related use and disclosure does not always require consent; secondary uses generally do.

Individual Rights: 30-day response time for access requests.

Breach Notification: Manitoba's PHIA was amended to include mandatory breach notification (s. 19.0.1, C.C.S.M. c. P33.5). Trustees must:

  • Notify affected individuals as soon as practicable when a privacy breach could reasonably be expected to create a real risk of significant harm
  • Also notify the Manitoba Ombudsman (the PHIA regulator) whenever individuals must be notified

Regulator: The Manitoba Ombudsman enforces PHIA.


Practical Considerations for Saskatchewan and Manitoba Businesses

Non-Healthcare Businesses

Your compliance programme is straightforward PIPEDA:

  • Privacy Officer designation
  • Privacy policy (website + available on request)
  • Consent processes for customer and employee data
  • Security safeguards
  • Breach response and register
  • Access request procedure (30-day OPC deadline)

The OPC in Ottawa is your regulator for complaints. No provincial privacy regulator exists for private-sector commercial activities in either province.

Healthcare Businesses

Your programme has two layers:

  1. HIPA (SK) or PHIA (MB) for patient/client health information — your primary obligation
  2. PIPEDA for non-health personal information (administrative records, employee data, billing that isn't part of the health record)

Cross-Provincial Operations

Saskatchewan and Manitoba businesses commonly serve customers across the Prairies and nationally. Cross-provincial commercial activities fall under PIPEDA (the federal law). There's no "multi-province coordination" issue in SK and MB the way there is in provinces with their own laws (PIPA in AB and BC) — PIPEDA governs both the provincial and cross-provincial aspects.


Resources for Saskatchewan and Manitoba Businesses

Saskatchewan

  • Saskatchewan Information and Privacy Commissioner (IPC): oipc.sk.ca — HIPA and FOIPP enforcement, guidance for health information trustees
  • OPC Canada: PIPEDA complaints and guidance for all private-sector businesses

Manitoba

  • Manitoba Ombudsman: ombudsman.mb.ca — PHIA enforcement, investigates health privacy complaints
  • OPC Canada: PIPEDA compliance for private-sector businesses

Compliance Checklist for SK and MB Businesses

All private-sector businesses:

  • Designate a Privacy Officer
  • Publish a PIPEDA-compliant privacy policy
  • Establish consent processes for customer and employee data
  • Implement security safeguards appropriate to data sensitivity
  • Create a breach response procedure and register
  • Build an access request response process (30-day deadline)
  • Train staff on privacy basics annually

Healthcare businesses (add):

  • Implement HIPA (SK) or PHIA (MB) compliant patient information policies
  • Establish patient access request procedures under the applicable health information act
  • Configure breach response procedures for health information under the applicable health information act
  • Review all health information technology vendors for HIPA/PHIA compliance

Frequently Asked Questions

Q: Does Saskatchewan have any provincial privacy regulator for retail or e-commerce businesses? A: No — Saskatchewan does not have a substantially similar private-sector privacy law. PIPEDA and the OPC govern all private-sector commercial activities. The Saskatchewan IPC handles health information (HIPA) only.

Q: We're a Manitoba employer. Is PIPEDA our employment law? A: PIPEDA applies to federally regulated employers (banks, airlines, telecoms). For provincially regulated Manitoba employers, there's no provincial private-sector privacy law covering employee data in Manitoba specifically. PIPEDA doesn't apply to provincially regulated employer-employee relationships in provinces without substantially similar legislation — but employment standards legislation and human rights law still protect employees' information. Consult an employment lawyer for Manitoba-specific guidance on employee privacy.

Q: A patient complaint in Winnipeg about our clinic's data practices — who do we deal with? A: The Manitoba Ombudsman enforces PHIA. For health information, the complaint goes there. For non-health personal information issues (e.g., billing contact data), the OPC handles PIPEDA complaints.


Canadian Compliance That Covers Every Province

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — Prairie business compliance, handled.

Related reading: PIPEDA Compliance Guide | Alberta Privacy Compliance | Ontario Privacy Compliance

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.