Skip to content
GlanceDeskJurisdiction

Home › Law library › PIPEDA

CA

PIPEDA

Personal Information Protection and Electronic Documents Act (PIPEDA)

Sourced. Last verified 9 October 2026

Canada (federal) Privacy

Status
In force. Replacement bill C-36 (Protecting Privacy and Consumer Data Act) tabled 15 Jun 2026; at second reading in the House of Commons, not yet law.
Who it applies to
Private-sector organizations handling personal info in commercial activity, plus federally regulated firms (banks, airlines, telecoms) incl. employee data. Applies to data crossing provincial or national borders, even in Alberta, BC and Quebec, which have their own similar laws.
Size thresholds
No size, revenue or volume thresholds; applies to any organization collecting, using or disclosing personal info in the course of commercial activity.
Regulator
Office of the Privacy Commissioner of Canada (OPC)
Breach or incident reporting
Report to the OPC and notify affected individuals as soon as feasible for any breach of security safeguards creating a real risk of significant harm (e.g., financial loss, identity theft, humiliation). Keep a record of every breach and provide it to the OPC on request.
Deadline to answer personal data requests
Access requests: respond within 30 days of receipt; may extend by up to 30 more days (or longer for format conversion) with written notice to the individual within the first 30 days.
Data protection officer
Must designate one or more individuals accountable for PIPEDA compliance and make their name or title known internally and externally (e.g., on the website).
Local representative
Being verified
Sending data abroad
Transfers for processing are allowed without extra consent if used for the original purpose. The organization stays accountable, must use contracts to ensure comparable protection, and must tell individuals their data may be processed abroad and accessed by foreign authorities.
Cookies and consent
Meaningful consent required. Opt-out consent for online behavioural advertising is acceptable only with clear, timely notice, easy and immediate opt-out, non-sensitive data and limited retention; avoid tracking children and uncontrollable trackers (fingerprinting, supercookies).
Maximum penalty
Fines up to C$100,000 per indictable offence (C$10,000 on summary conviction) for knowingly violating breach-reporting/record rules or obstructing the Commissioner. Proposed Bill C-36 would raise maximums to C$10M or 3% of gross global revenue.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Bill C-27 (CPPA/AIDA) died when Parliament was prorogued in Jan 2025. Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled 15 Jun 2026; it would replace PIPEDA's privacy part, create a new regulator, and add deletion, portability and ADM rights. Still at second reading.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].