Canadian Privacy
Part of the PIPEDA guide

What is PIPEDA? Meaning, Principles and Who Must Comply

What PIPEDA is, who it applies to, and the 10 fair information principles Canadian businesses must follow — in plain language, with official sources.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
12 min read
PIPEDA
Canadian Privacy Law
Privacy Basics
SMB Guide
Data Protection

If you run a business in Canada and collect any information about your customers, employees, or prospects, you need to understand PIPEDA.

This guide explains PIPEDA in plain language — no law degree required.

Last updated: April 2026

What is PIPEDA?

PIPEDA stands for the Personal Information Protection and Electronic Documents Act. It is Canada's federal private-sector privacy law, enacted in 2000 and substantially strengthened in 2018 with the addition of mandatory breach reporting requirements.

PIPEDA governs how private-sector organisations collect, use, and disclose personal information in the course of commercial activities. The Office of the Privacy Commissioner of Canada (OPC) — at priv.gc.ca — enforces the law and can investigate complaints, conduct audits, and publish findings.

What does "personal information" mean under PIPEDA?

Personal information is broadly defined as any information about an identifiable individual. This includes:

  • Full name, address, phone number, email address
  • Age, sex, national or ethnic origin
  • Identification numbers (SIN, health card, driver's licence)
  • Income, financial records, purchase history
  • Medical and health records
  • Employee performance reviews
  • Credit history and banking information
  • Video surveillance footage and photos
  • IP addresses and browsing history (in most cases)

If you can link data to a specific person — directly or indirectly — it is personal information under PIPEDA.

Who Does PIPEDA Apply To?

PIPEDA applies to private-sector organisations that collect, use, or disclose personal information in the course of commercial activities, including:

  • Sole proprietorships, partnerships, and corporations
  • Non-profits engaged in commercial activities (selling products, renting space)
  • Federally regulated organisations (banks, telecoms, airlines, rail) nationwide
  • Any organisation that operates across provincial borders

Provincial variations and substantially similar laws

Three provinces have privacy legislation deemed substantially similar to PIPEDA:

ProvinceLawApplies To
QuebecAct respecting the protection of personal information in the private sector (amended by Law 25)Enterprises in Quebec (other than federal works, undertakings or businesses)
AlbertaPIPA AlbertaMost private-sector organisations
British ColumbiaPIPA BCMost private-sector organisations

If your business operates exclusively within Alberta or BC and isn't federally regulated, provincial PIPA law applies instead of PIPEDA for provincially governed activities. In Quebec, organizations covered by the provincial private sector Act (as amended by Law 25) are exempt from PIPEDA for collection, use and disclosure of personal information that occurs within Quebec (Organizations in the Province of Quebec Exemption Order); federal works, undertakings and businesses remain under PIPEDA — see our Quebec Law 25 guide.

When a provincial health-privacy law applies instead

Ontario, Manitoba, Saskatchewan and the Atlantic provinces have no general private-sector privacy law of their own, so PIPEDA covers commercial activities there. Personal health information is the main exception: several of these provinces have their own health-privacy laws — Ontario's PHIPA among them — which apply instead of PIPEDA to the custodians they cover. If you handle health information, confirm whether your province's health-privacy law governs you before assuming PIPEDA does.

PIPEDA's 10 Fair Information Principles

The PIPEDA principles — 10 Fair Information Principles drawn from the CSA Model Privacy Code — are what the Act is built on. A compliance programme has to address all ten.

1. Accountability

Your organisation must designate someone responsible for PIPEDA compliance — typically called a Privacy Officer. This person doesn't need to be a lawyer, but they must have authority and resources to enforce your privacy policies.

2. Identifying Purposes

Before collecting personal information, you must identify why you are collecting it. You can't collect data "just in case." If you collect email addresses for order confirmations, you can't later use them for unrelated marketing without fresh consent.

3. Consent

Individuals must consent to the collection, use, or disclosure of their personal information. Consent can be express (opt-in checkbox) or implied (providing a business card), depending on the sensitivity of the information.

4. Limiting Collection

You may only collect personal information that is necessary for the identified purposes. Don't collect a customer's date of birth if you only need their shipping address.

5. Limiting Use, Disclosure, and Retention

Personal information must only be used or disclosed for the purposes for which it was collected. Once no longer needed, it must be destroyed or anonymised.

6. Accuracy

Personal information must be as accurate, complete, and up-to-date as necessary for the purpose. Outdated records that lead to incorrect decisions violate this principle.

7. Safeguards

You must protect personal information using security safeguards appropriate to the sensitivity of the information. For basic contact data, this might mean password-protected systems. For health or financial data, encryption and access controls are expected.

8. Openness

Your privacy practices must be transparent and publicly available. This typically means publishing a privacy policy on your website that describes what you collect, why, and how people can exercise their rights.

9. Individual Access

Upon request, individuals have the right to access their personal information held by your organisation and correct any inaccuracies. You must respond within 30 days.

10. Challenging Compliance

Individuals have the right to challenge your compliance with PIPEDA by filing a complaint with your organisation first, and then with the OPC if unsatisfied.

What Are the Penalties for PIPEDA Non-Compliance?

Many business owners assume PIPEDA has no real teeth. That is changing rapidly.

Offences under PIPEDA (s. 28) — an organization that knowingly does any of the following faces a fine of up to $10,000 on summary conviction or up to $100,000 on indictment:

  • Failing to report or notify a breach as required (s. 10.1) or failing to keep breach records (s. 10.3(1))
  • Failing to retain information that is the subject of an access request until the individual's recourse is exhausted (s. 8(8))
  • Retaliating against a whistleblower employee (s. 27.1(1))
  • Obstructing the Commissioner in an investigation or audit

Beyond fines, the real cost is reputational damage. The OPC publishes investigation findings — including company names — on its public website. A single publicised finding can cost far more than any fine.

Mandatory Breach Reporting Under PIPEDA

Since November 2018, PIPEDA requires organisations to:

  1. Report to the OPC any breach that poses a "real risk of significant harm" to individuals
  2. Notify affected individuals of such breaches directly
  3. Maintain breach records for a minimum of 24 months

Knowingly failing to report a qualifying breach is itself an offence under PIPEDA (s. 28). The OPC can investigate whether your breach notification was timely and appropriate.

How to Start Your PIPEDA Compliance Programme

Getting compliant doesn't have to mean hiring expensive lawyers. Here is a practical starting framework:

Week 1–2: Inventory

  • Map every type of personal information your business collects
  • Document where it's stored, who has access, and how long you keep it

Week 3–4: Policies

  • Draft or update your Privacy Policy and publish it on your website
  • Create internal procedures for breach response and access requests

Month 2: Training and Consent

  • Train all staff on PIPEDA basics
  • Audit your consent mechanisms (sign-up forms, checkout flows, contracts)

Ongoing: Monitoring

  • Review vendor contracts to ensure third-party compliance
  • Conduct annual privacy reviews as regulations evolve

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Key Differences Between PIPEDA and GDPR

Many Canadian businesses that serve European customers ask how PIPEDA compares to the EU's GDPR:

FeaturePIPEDAGDPR
Consent modelImplied consent often acceptableGenerally requires opt-in
Right to erasureLimited right to deletionStrong "right to be forgotten"
PenaltiesFines up to $100K for specified offences (s. 28)Up to 4% of global annual revenue
Data transfersAdequate safeguards requiredStrict restrictions
Breach notificationAs soon as feasible if real risk of significant harm (no fixed hours)72-hour notification required

Canada has been granted EU adequacy status under GDPR, meaning personal data can flow from the EU to Canada without additional safeguards — but only under PIPEDA. Quebec's Law 25 adds stricter requirements closer to GDPR for businesses in that province.

Frequently Asked Questions

Q: Does PIPEDA apply to employee information? A: PIPEDA's application to employee data is limited to federally regulated employers. In most provinces, employee privacy is covered by other laws or employment standards. However, PIPEDA does apply to job applicant information in federally regulated sectors.

Q: Do I need a privacy policy if I'm a small business? A: Yes. PIPEDA's Openness Principle requires your privacy practices to be readily available to individuals, and a clear, accurate privacy policy is the usual way to meet it. It is not by itself proof of compliance with the rest of the Act, and a policy protects no one if your actual practices differ from what it describes.

Q: What's the difference between PIPEDA and CASL? A: PIPEDA governs how you handle personal information broadly. CASL (Canada's Anti-Spam Legislation) specifically governs commercial electronic messages — emails, texts, and app notifications. You need to comply with both. See our CASL compliance guide for details.

Q: How often do I need to update my privacy policy? A: Review your privacy policy at least annually or whenever you make significant changes to how you collect or use data. Document the review with a date — something like "Last updated: April 2026."

Q: Can I use a US-based software platform and still be PIPEDA compliant? A: Potentially yes, but you must inform customers that their data may be stored or processed outside Canada, and ensure the third party has appropriate safeguards in place. Our cross-border data transfers guide covers this in detail.


Start Your Compliance Journey Today

Understanding PIPEDA is the first step. Implementing it is where most businesses struggle — especially without a dedicated compliance team.

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Get your free compliance check — about two minutes, no account needed.

For questions about PIPEDA compliance, visit the Office of the Privacy Commissioner or explore our PIPEDA compliance guide.

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.