The federal layer: PIPEDA
The Personal Information Protection and Electronic Documents Act applies to organisations that collect, use or disclose personal information in the course of commercial activity. It is built on ten fair information principles set out in Schedule 1, covering accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.
PIPEDA is deliberately principles-based rather than prescriptive. The Office of the Privacy Commissioner of Canada investigates complaints and issues findings, but has no order-making power of its own. Enforcement runs through the Federal Court.
Substantially similar provincial laws
Where a province has enacted legislation deemed substantially similar to PIPEDA, that law governs intra-provincial activity instead. Alberta and British Columbia each have a Personal Information Protection Act, and Quebec has its own private-sector regime. PIPEDA continues to apply to federal works, undertakings and businesses, and to personal information crossing provincial or national borders.
Health information is handled separately again, with dedicated statutes such as Ontario PHIPA governing custodians of personal health information.
Quebec Law 25
Law 25 modernised Quebec privacy law in phased stages from 2022 through 2024. It introduced mandatory privacy officer designation, confidentiality incident reporting, privacy impact assessments for information system projects and cross-border transfers, explicit consent for sensitive information, transparency around automated decision-making, and a right to data portability.
Penalties are the most significant in Canada: administrative monetary penalties up to CAD 10 million or 2 percent of worldwide turnover, and penal fines up to CAD 25 million or 4 percent of worldwide turnover, whichever is greater.
Breach reporting
Since November 2018, PIPEDA requires organisations to report breaches of security safeguards to the Privacy Commissioner, and notify affected individuals, where the breach creates a real risk of significant harm. Organisations must also keep a record of every breach, regardless of whether it met the notification threshold, and retain those records for 24 months.
Quebec applies a parallel confidentiality incident regime with its own reporting duties and register requirement.
Cross-border transfers
PIPEDA treats transfers to a third party for processing as a use, not a disclosure, so no additional consent is required, but the transferring organisation remains accountable and must use contractual or other means to provide a comparable level of protection. Quebec goes further, requiring a privacy impact assessment before any transfer outside the province and a determination that the information will receive adequate protection.
Bill C-27 and the CPPA
Bill C-27, the Digital Charter Implementation Act, proposed replacing PIPEDA's private-sector provisions with the Consumer Privacy Protection Act, creating a Personal Information and Data Protection Tribunal, and enacting the Artificial Intelligence and Data Act. The bill died on the Order Paper when Parliament was prorogued in January 2025. Its substance remains the clearest signal of the direction of federal reform, including order-making powers and penalties up to 5 percent of global revenue.
What to do now
- Map which regime governs each processing activity: federal, Alberta, BC, Quebec or a health statute.
- Designate a privacy officer and publish the contact details.
- Build a breach register that captures every incident, not just reportable ones.
- Run privacy impact assessments for Quebec transfers and system projects.
- Review processor contracts for comparable-protection clauses.
- Document consent flows, with explicit consent paths for sensitive information.