PIPEDA Explained: Canada's Federal Privacy Law

PIPEDA, the Personal Information Protection and Electronic Documents Act (SC 2000, c 5), is Canada's federal law governing how private-sector organizations collect, use, and disclose personal information in the course of commercial activity, and it remains fully in force today.
What Is PIPEDA?
The Personal Information Protection and Electronic Documents Act received royal assent on April 13, 2000, and was phased in between 2001 and 2004. Parliament designed it to balance two things at once: an individual's right to have their personal information protected, and an organization's legitimate need to collect, use, or disclose personal information for reasonable business purposes.
PIPEDA is not a licensing regime and it does not require organizations to register with the government. Instead, it sets binding rules that private-sector organizations must follow whenever personal information changes hands as part of a commercial activity, backed by a complaint and investigation process run by the Office of the Privacy Commissioner of Canada.
Who PIPEDA Applies To
PIPEDA applies broadly, but the details matter.
- Private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity, in any province or territory that does not have its own substantially similar private-sector privacy law.
- Federally regulated works and undertakings, such as banks, airlines, railways, telecommunications carriers, and interprovincial trucking companies, which must follow PIPEDA for both their customers' and their own employees' personal information, regardless of which province they operate in.
- Any organization, anywhere in Canada, when personal information crosses a provincial or national border, since provincial substantially similar laws only displace PIPEDA for activity that stays within that province.
Nonprofits, political parties, and organizations that are not engaged in commercial activity generally fall outside PIPEDA's scope, unless they are selling, renting, or trading membership or donor lists as a commercial activity.
What Counts as Personal Information
PIPEDA defines personal information broadly: any factual or subjective information, recorded or not, about an identifiable individual. That includes a person's age, name, ID numbers, income, ethnic origin, blood type, opinions, evaluations, comments, social status, and disciplinary actions, among other categories.
An important carve-out is business contact information used strictly to communicate with someone in their professional capacity, such as a name, title, business address, or work phone number. That information generally falls outside PIPEDA's definition of personal information when it is used for that purpose.
The 10 Fair Information Principles
PIPEDA is built around Schedule 1, which sets out 10 fair information principles that every covered organization must follow.
| Principle | What It Requires |
|---|---|
| 1. Accountability | The organization is responsible for personal information under its control and must designate someone accountable for compliance. |
| 2. Identifying Purposes | The purposes for collecting personal information must be identified before or at the time of collection. |
| 3. Consent | The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except in limited, specific circumstances. |
| 4. Limiting Collection | Collection must be limited to what is necessary for the identified purposes and must be gathered by fair and lawful means. |
| 5. Limiting Use, Disclosure, and Retention | Personal information may be used or disclosed only for the purposes for which it was collected, unless the individual consents or the law requires otherwise, and it must be retained only as long as necessary. |
| 6. Accuracy | Personal information must be as accurate, complete, and up to date as necessary for its intended use. |
| 7. Safeguards | Personal information must be protected by security safeguards appropriate to its sensitivity. |
| 8. Openness | An organization must make information about its personal information policies and practices readily available. |
| 9. Individual Access | On request, an individual must be told whether an organization holds information about them, be given access to it, and be able to challenge its accuracy and completeness. |
| 10. Challenging Compliance | An individual must be able to challenge an organization's compliance with these principles, first to the person accountable inside the organization, and then to the OPC. |
Meaningful Consent: Express vs Implied
Consent is the principle organizations get wrong most often, which is why the OPC, together with Alberta's and British Columbia's privacy commissioners, published Guidelines for Obtaining Meaningful Consent that took effect January 1, 2019.
Consent can be express, where an individual clearly opts in through an affirmative action, or implied, where consent can reasonably be inferred from the individual's conduct and the context. As a general rule, sensitive personal information, such as health information, financial details, or genetic information, requires express consent rather than implied consent.
To be meaningful, consent generally must let the individual understand, in reasonably plain language, what information is being collected, who it will be shared with, why, and what risks or consequences follow from providing it. Consent obtained by bundling it into lengthy, unclear terms of service is unlikely to hold up if the OPC investigates.
Your Right of Access and to Challenge Compliance
Under Principles 9 and 10, an individual can ask an organization whether it holds personal information about them, request access to that information, and ask that inaccurate or incomplete information be corrected. If an organization refuses or does not respond adequately, the individual can challenge that response internally, and ultimately file a complaint with the OPC.
There are limited exceptions to the access right, including where disclosure would reveal personal information about another individual, would compromise an ongoing investigation, or is restricted by solicitor-client privilege.
Mandatory Breach Reporting Since November 2018
Amendments brought in by the Digital Privacy Act made breach reporting mandatory under PIPEDA as of November 1, 2018. An organization must report a breach of security safeguards to the OPC, and notify affected individuals, whenever the breach creates a real risk of significant harm, a standard commonly shortened to RROSH.
Two factors drive the RROSH assessment: the sensitivity of the personal information involved, and the probability that the information has been, is being, or will be misused. Reports to the OPC and notifications to affected individuals must happen as soon as feasible after the organization determines a breach meets that threshold, and the organization must also notify any other organization that may be able to reduce the resulting risk, such as a bank that could flag a compromised account.
Separately from the reporting duty, PIPEDA requires every organization to keep a record of all breaches of security safeguards involving personal information under its control, whether or not a given breach meets the real-risk-of-significant-harm threshold. The OPC can request and audit these records at any time, so under-reporting is not a way to avoid scrutiny.
How the OPC Enforces PIPEDA
The Office of the Privacy Commissioner of Canada investigates complaints from individuals and can also launch its own investigations. At the end of an investigation, the OPC issues findings, which typically include recommendations for the organization to come into compliance, and it can negotiate compliance agreements with organizations.
What the OPC cannot do under PIPEDA is impose a fine or a binding order on its own authority. If an organization does not follow the OPC's recommendations, the Commissioner or the original complainant can apply to the Federal Court, which has the power to order corrective action and award damages, including for humiliation. This two-step structure, an investigation followed by a possible Federal Court application, is a real and often-criticized limit on PIPEDA's enforcement teeth, and it is sharply different from Quebec's regime under Law 25, where the province's Commission d'acces a l'information can issue meaningful administrative monetary penalties directly.
Where PIPEDA Does Not Apply
PIPEDA is not the only privacy statute in Canada, and it is easy to misapply it in the wrong context.
- Quebec, Alberta, and British Columbia each have a private-sector privacy law that has been declared substantially similar to PIPEDA, so that provincial law applies instead of PIPEDA for activity that occurs entirely within that province. See Alberta and BC PIPA for how those two acts work.
- Ontario's PHIPA and similar health-sector statutes in other provinces govern personal health information held by health information custodians, and operate alongside PIPEDA rather than replacing it for other private-sector activity.
- The federal public sector is governed by the Privacy Act, RSC 1985, c P-21, a completely different statute that regulates how federal government institutions handle personal information, not private businesses. See the Privacy Act explained for that side of Canadian privacy law.
Even inside Quebec, Alberta, or British Columbia, PIPEDA continues to apply to federally regulated organizations and to personal information that moves across a provincial or international border.
Bill C-27 Is Dead: PIPEDA Remains in Force
Bill C-27, the Digital Charter Implementation Act, 2022, was introduced in the House of Commons in June 2022. It would have repealed most of PIPEDA's private-sector provisions and replaced them with a new Consumer Privacy Protection Act, created a Personal Information and Data Protection Tribunal, and enacted Canada's first dedicated artificial intelligence statute, the Artificial Intelligence and Data Act.
The bill spent roughly two and a half years moving through committee study at the House of Commons Standing Committee on Industry and Technology without reaching third reading. When Parliament was prorogued on January 6, 2025, Bill C-27 died on the Order Paper along with every other bill that had not yet received royal assent, and the committee studying it was dissolved.
As of this writing, Bill C-27 has not been reintroduced in any form, and neither the Consumer Privacy Protection Act nor the Artificial Intelligence and Data Act is Canadian law. Do not rely on any source claiming the CPPA "has passed," "replaces PIPEDA," or "is now in force." PIPEDA, in its current, pre-C-27 form, remains the governing federal private-sector privacy statute in Canada, and will continue to be until a future bill is introduced, passed, and receives royal assent.
PIPEDA and Canada's One-Party Consent Recording Law
PIPEDA and Canada's recording laws answer two different questions, and it helps to keep them separate. Whether you are allowed to record a conversation is a criminal law question, governed by Criminal Code s 184(1), which makes it an offence to wilfully intercept a private communication, and s 184(2)(a), which creates a one-party-consent exception. Because of that exception, recording a conversation you are personally a party to is lawful across every Canadian province and territory, as explained in full on Canada's recording laws.
PIPEDA becomes relevant once a business or organization is the one doing the recording, or once a recording is used, shared, or published. An organization that records calls with customers, for example, is collecting personal information in the course of a commercial activity, which means the fair information principles, including identifying the purpose and obtaining meaningful consent, apply to that recording even though the underlying act of recording is not a crime. For the same reason, publishing or disclosing a recording that identifies someone can trigger PIPEDA or a provincial privacy tort even when making the recording itself broke no law. For the broader country-level picture of how these rules interact, see Canada's data privacy laws.
Bill C-15 and the New Data-Mobility Right
PIPEDA is no longer entirely unchanged. Bill C-15, the Budget 2025 Implementation Act, No. 1, received Royal Assent on March 26, 2026 (SC 2026, c 3) and amended PIPEDA to add a data-mobility framework, the first federal data-portability right in Canadian law. In principle it will let an individual direct that personal information an organization holds about them be disclosed to another organization in a standard, machine-readable format.
The practical point for now is that the right is not yet in force. It comes into force on a day to be fixed by order of the Governor in Council, and it becomes operative only once the government makes regulations establishing sector-specific data-mobility frameworks. Those are expected to roll out industry by industry, starting with open banking under the companion consumer-driven banking legislation. Until those regulations are made, no organization is yet obliged to act on the new provision, and the rest of PIPEDA continues to apply exactly as set out above.
The Bottom Line
PIPEDA has governed private-sector data handling in Canada since 2000, its 10 principles and 2018 breach-reporting rules remain fully enforceable today, and the widely anticipated Consumer Privacy Protection Act is not law. PIPEDA was amended in March 2026 to add a data-mobility framework, but that new right is not yet in force. Businesses operating in Quebec, Alberta, or British Columbia should check their applicable provincial law first, but everyone else, and every federally regulated employer, is governed by PIPEDA as written.
Disclaimer: This article provides general information about Canadian federal privacy law and does not constitute legal advice. Privacy legislation changes over time, including the possibility of a future bill replacing or amending PIPEDA. Confirm current requirements with the Office of the Privacy Commissioner of Canada or a qualified privacy lawyer before relying on any specific interpretation.
Frequently Asked Questions
What does PIPEDA stand for?
PIPEDA stands for the Personal Information Protection and Electronic Documents Act, SC 2000, c 5. It is the federal statute that sets the rules for how private-sector organizations in Canada handle personal information in the course of commercial activity.
Does PIPEDA apply to my small business?
Generally yes, if your business collects, uses, or discloses personal information as part of a commercial activity and operates in a province without its own substantially similar law, or if the information crosses provincial or national borders. Businesses that operate wholly within Quebec, Alberta, or British Columbia usually fall under that province's private-sector law instead.
What happens if an organization does not report a data breach under PIPEDA?
Knowingly failing to report a breach that poses a real risk of significant harm, failing to notify affected individuals, or failing to keep the required breach records is itself an offence under PIPEDA and can lead to prosecution, separate from any Federal Court remedy for the underlying breach.
Can the Privacy Commissioner fine a company under PIPEDA?
No, not directly. The OPC can investigate, audit, and publish findings and recommendations, and it can enter into compliance agreements, but it has no order-making or administrative-monetary-penalty power under PIPEDA. A binding order or damages award requires the Commissioner or the complainant to apply to the Federal Court.
Is Bill C-27 or the Consumer Privacy Protection Act the law in Canada right now?
No. Bill C-27 died on the Order Paper when Parliament was prorogued on January 6, 2025, and it was never reintroduced or passed. The Consumer Privacy Protection Act and the Artificial Intelligence and Data Act it would have created are not law. PIPEDA remains the operative federal private-sector privacy statute.
Does PIPEDA apply in Quebec?
Quebec's private-sector privacy law, as amended by Law 25, has been declared substantially similar to PIPEDA, so it applies instead of PIPEDA for activity that occurs entirely within Quebec. PIPEDA still applies to federally regulated businesses operating in Quebec and to personal information that crosses provincial or international borders.
Updates
Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent, amending PIPEDA to add a data-mobility framework. The new data-portability right is not yet in force: it comes into force on a day fixed by order of the Governor in Council, pending regulations establishing sector-specific data-mobility frameworks.
Parliament was prorogued, killing Bill C-27 (the Digital Charter Implementation Act, 2022) on the Order Paper before it could pass. The bill has not been reintroduced. PIPEDA continues to be the operative federal private-sector privacy law, and neither the proposed Consumer Privacy Protection Act nor the Artificial Intelligence and Data Act is in force.
Sources and References
- Personal Information Protection and Electronic Documents Act, SC 2000, c 5 (full text)(laws-lois.justice.gc.ca).gov
- Office of the Privacy Commissioner of Canada - The Personal Information Protection and Electronic Documents Act (PIPEDA)(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada - PIPEDA requirements in brief(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada - What you need to know about mandatory reporting of breaches of security safeguards(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada - Assess if a privacy breach poses a real risk of significant harm(priv.gc.ca).gov
- Office of the Privacy Commissioner of Canada - Guidelines for obtaining meaningful consent(priv.gc.ca).gov
- Privacy Act, RSC 1985, c P-21 (full text)(laws-lois.justice.gc.ca).gov
- Criminal Code, RSC 1985, c C-46, s 184 (interception of private communications)(laws-lois.justice.gc.ca).gov
- R v Duarte, [1990] 1 SCR 30 (CanLII)(canlii.org)
- Parliament of Canada, LEGISinfo - Bill C-27, Digital Charter Implementation Act, 2022 (44th Parliament, 1st session)(parl.ca).gov
- Bill C-15, Budget 2025 Implementation Act, No. 1 (LEGISinfo)(parl.ca).gov