Home › Law library › PIPEDA
CA
PIPEDA
Personal Information Protection and Electronic Documents Act (PIPEDA)
Sourced. Last verified 9 October 2026
Canada (federal) Privacy
- Status
- In force. Replacement bill C-36 (Protecting Privacy and Consumer Data Act) tabled 15 Jun 2026; at second reading in the House of Commons, not yet law.
- Who it applies to
- Private-sector organizations handling personal info in commercial activity, plus federally regulated firms (banks, airlines, telecoms) incl. employee data. Applies to data crossing provincial or national borders, even in Alberta, BC and Quebec, which have their own similar laws.
- Size thresholds
- No size, revenue or volume thresholds; applies to any organization collecting, using or disclosing personal info in the course of commercial activity.
- Regulator
- Office of the Privacy Commissioner of Canada (OPC)
- Breach or incident reporting
- Report to the OPC and notify affected individuals as soon as feasible for any breach of security safeguards creating a real risk of significant harm (e.g., financial loss, identity theft, humiliation). Keep a record of every breach and provide it to the OPC on request.
- Deadline to answer personal data requests
- Access requests: respond within 30 days of receipt; may extend by up to 30 more days (or longer for format conversion) with written notice to the individual within the first 30 days.
- Data protection officer
- Must designate one or more individuals accountable for PIPEDA compliance and make their name or title known internally and externally (e.g., on the website).
- Local representative
- Being verified
- Sending data abroad
- Transfers for processing are allowed without extra consent if used for the original purpose. The organization stays accountable, must use contracts to ensure comparable protection, and must tell individuals their data may be processed abroad and accessed by foreign authorities.
- Cookies and consent
- Meaningful consent required. Opt-out consent for online behavioural advertising is acceptable only with clear, timely notice, easy and immediate opt-out, non-sensitive data and limited retention; avoid tracking children and uncontrollable trackers (fingerprinting, supercookies).
- Maximum penalty
- Fines up to C$100,000 per indictable offence (C$10,000 on summary conviction) for knowingly violating breach-reporting/record rules or obstructing the Commissioner. Proposed Bill C-36 would raise maximums to C$10M or 3% of gross global revenue.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Appoint a privacy officer accountable for compliance and publish their name or title.
- Obtain meaningful consent and limit collection, use and disclosure to identified purposes.
- Answer access requests within 30 days (one extension of up to 30 days with notice).
- Report real-risk-of-significant-harm breaches to the OPC and notify affected people as soon as feasible.
- Keep a record of every security breach and provide it to the OPC on request.
- Use contracts to ensure comparable protection for data sent to processors, including abroad, and disclose foreign processing.
Recent changes
Bill C-27 (CPPA/AIDA) died when Parliament was prorogued in Jan 2025. Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled 15 Jun 2026; it would replace PIPEDA's privacy part, create a new regulator, and add deletion, portability and ADM rights. Still at second reading.
Sources
- Primary source: https://laws-lois.justice.gc.ca/eng/acts/P-8.6/
- Second source: https://gowlingwlg.com/en/insights-resources/articles/2026/ottawa-tables-long-awaited-federal-privacy-reform-legislation
- Regulator: Office of the Privacy Commissioner of Canada (OPC)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].