contact@vedhacon.com Data privacy consultancy across 50+ jurisdictions
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Canada

PIPEDA, Law 25 and the road to Bill C-27

Canada runs a federal private-sector statute, a set of substantially similar provincial regimes, and a Quebec law that now sets the highest bar in the country. This guide separates what applies where, and what each one actually asks you to do.

2001PIPEDA in force
10Fair information principles
$100kMax PIPEDA penalty (CAD)
4%Law 25 max global turnover fine

The federal layer: PIPEDA

The Personal Information Protection and Electronic Documents Act applies to organisations that collect, use or disclose personal information in the course of commercial activity. It is built on ten fair information principles set out in Schedule 1, covering accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.

PIPEDA is deliberately principles-based rather than prescriptive. The Office of the Privacy Commissioner of Canada investigates complaints and issues findings, but has no order-making power of its own. Enforcement runs through the Federal Court.

Substantially similar provincial laws

Where a province has enacted legislation deemed substantially similar to PIPEDA, that law governs intra-provincial activity instead. Alberta and British Columbia each have a Personal Information Protection Act, and Quebec has its own private-sector regime. PIPEDA continues to apply to federal works, undertakings and businesses, and to personal information crossing provincial or national borders.

Health information is handled separately again, with dedicated statutes such as Ontario PHIPA governing custodians of personal health information.

Quebec Law 25

Law 25 modernised Quebec privacy law in phased stages from 2022 through 2024. It introduced mandatory privacy officer designation, confidentiality incident reporting, privacy impact assessments for information system projects and cross-border transfers, explicit consent for sensitive information, transparency around automated decision-making, and a right to data portability.

Penalties are the most significant in Canada: administrative monetary penalties up to CAD 10 million or 2 percent of worldwide turnover, and penal fines up to CAD 25 million or 4 percent of worldwide turnover, whichever is greater.

Breach reporting

Since November 2018, PIPEDA requires organisations to report breaches of security safeguards to the Privacy Commissioner, and notify affected individuals, where the breach creates a real risk of significant harm. Organisations must also keep a record of every breach, regardless of whether it met the notification threshold, and retain those records for 24 months.

Quebec applies a parallel confidentiality incident regime with its own reporting duties and register requirement.

Cross-border transfers

PIPEDA treats transfers to a third party for processing as a use, not a disclosure, so no additional consent is required, but the transferring organisation remains accountable and must use contractual or other means to provide a comparable level of protection. Quebec goes further, requiring a privacy impact assessment before any transfer outside the province and a determination that the information will receive adequate protection.

Bill C-27 and the CPPA

Bill C-27, the Digital Charter Implementation Act, proposed replacing PIPEDA's private-sector provisions with the Consumer Privacy Protection Act, creating a Personal Information and Data Protection Tribunal, and enacting the Artificial Intelligence and Data Act. The bill died on the Order Paper when Parliament was prorogued in January 2025. Its substance remains the clearest signal of the direction of federal reform, including order-making powers and penalties up to 5 percent of global revenue.

What to do now