EnglishFrançais
Canada flag

Canada

Canada Data Privacy Laws: PIPEDA & Provincial Guide (2026)

Independently fact-checked against primary sources (last audited September 9, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 9, 2026. · 21 primary sources cited on this page. How we verify our legal content

Canada Data Privacy Laws: PIPEDA & Provincial Guide (2026)

Frequently Asked Questions

Does PIPEDA apply to all businesses in Canada?

PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity across Canada. However, in Alberta, British Columbia, and Quebec, provincial privacy laws deemed substantially similar to PIPEDA apply instead for intra-provincial commercial activity. PIPEDA still applies to federally regulated industries (banking, telecom, airlines) and to cross-border data transfers regardless of province. In all other provinces and territories, PIPEDA applies by default.

What happens if my organization suffers a data breach in Canada?

Under PIPEDA, you must assess whether the breach creates a real risk of significant harm (RROSH). If it does, you must report it to the Office of the Privacy Commissioner as soon as feasible, notify affected individuals directly, and notify any third-party organization that could reduce the risk of harm. You must also maintain records of all security incidents for at least 24 months, whether or not they triggered reporting. Knowingly failing to report or maintain records can result in fines up to CAD $100,000 per offence under PIPEDA s. 28. Quebec organizations face parallel obligations under Law 25.

How does Quebec Law 25 compare to the GDPR?

Quebec Law 25 is the closest North American equivalent to the GDPR. It requires explicit opt-in consent for cookies and tracking technologies, mandates a Privacy Impact Assessment for any project to acquire, develop or overhaul an information system involving personal information (s. 3.3) and before communicating personal information outside Quebec (s. 17), provides a private right of action with minimum $1,000 punitive damages, and imposes fines up to CAD $25 million or 4% of worldwide revenue for organizations. Key differences include Quebec-specific biometric filing requirements (prior disclosure to the CAI for identity verification, and disclosure at least 60 days before a biometric database is brought into service), individual penal caps of $100,000, and the absence of a formal DPO certification process comparable to GDPR Article 37.

Can Canadian organizations transfer personal data to other countries?

Yes. PIPEDA does not prohibit cross-border data transfers but requires organizations to ensure a comparable level of protection through contractual or other means. The transferring organization remains accountable for the data regardless of where it is processed. Quebec Law 25 is stricter, requiring a Privacy Impact Assessment before any transfer outside the province. The EU has recognized PIPEDA as providing adequate protection, allowing data to flow from the EU to PIPEDA-covered Canadian organizations without standard contractual clauses.

What is the current status of Canadian federal privacy reform?

Bill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act, died on the Order Paper in January 2025 when Parliament was prorogued. Its replacement, Bill C-36, was given first reading on June 15, 2026 and is at second reading in the House of Commons. It would enact the Protecting Privacy and Consumer Data Act, repeal Part 1 of PIPEDA, and allow administrative penalties of up to the greater of $10 million and 3% of gross global revenue. It is not law. Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent on March 26, 2026 and adds a data mobility framework to PIPEDA, but that Division is not yet in force. As of September 2026, PIPEDA still governs.

What did the OpenAI ChatGPT privacy investigation find?

In PIPEDA Findings #2026-002 (May 6, 2026), the OPC and three provincial regulators held that 'publicly available' information online is not exempt from privacy law obligations when collected for AI training. They accepted that developing and deploying ChatGPT is an appropriate purpose, but found that the manner in which OpenAI initially collected personal information from internet sources to train GPT-3.5 and 4, and the scale and nature of that collection, was overbroad and therefore inappropriate under PIPEDA s. 5(3). On consent, the OPC accepted that OpenAI may rely on implied consent where the privacy risk is significantly and meaningfully mitigated, and found the matter well-founded and conditionally resolved. The BC and Alberta commissioners found the consent issue well-founded and unresolved. The CAI found the appropriate-purposes, individual-rights and accountability issues conditionally resolved and the consent and retention issues unresolved.

Is there a right to be forgotten in Canada?

Canada does not have an explicit statutory right to erasure equivalent to GDPR Article 17. However, PIPEDA's retention limitation principle requires organizations to destroy personal information no longer needed for the purpose for which it was collected. In August 2025, the OPC's Google delist finding (PIPEDA Findings #2025-002) confirmed a limited right to delist under PIPEDA: in circumstances where a reasonable person would find it inappropriate for a search engine to continue returning links to personal information, an individual may request de-indexing. Quebec Law 25 provides an explicit right to de-indexing for digital content.

Does federal data portability apply to Canadian organizations now?

No. Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent on March 26, 2026 and adds Division 1.2 to PIPEDA, under which an organization would have to disclose, on request, the personal information it collected from an individual to an organization that individual designates, provided both are subject to a data mobility framework set by regulation. Section 398 of that Act defers the Division to a day fixed by order of the Governor in Council. No order has been made and no framework regulations exist, so there is no federal portability obligation today. Quebec Law 25 portability has been in force since September 22, 2024.

What is the appropriate purposes test under PIPEDA?

Section 5(3) of PIPEDA requires that an organization may only collect, use, or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances. This test is separate from consent: even where consent is obtained, collection or use for an inappropriate purpose violates the Act. The OPC applied this test in the 2026 OpenAI investigation, accepting that developing and deploying ChatGPT was an appropriate purpose but finding that the manner in which OpenAI initially collected personal information from internet sources, and the scale and nature of that collection, was overbroad and therefore inappropriate.

How does Alberta's PIPA differ from PIPEDA?

Alberta's Personal Information Protection Act (SA 2003, c P-6.5) is substantially similar to PIPEDA and displaces it for intra-provincial private-sector activity. The OIPC-AB enforces Alberta PIPA rather than the federal OPC. Key practical differences include: the OIPC-AB can make binding orders under Alberta PIPA (the federal OPC cannot directly order compliance under PIPEDA), and Alberta PIPA's breach notification threshold and scope differ slightly from PIPEDA's. Alberta is currently conducting reform consultations following the Standing Committee's February 2025 report, which recommended adding administrative monetary penalty powers to the OIPC-AB.

Updates

Corrected the federal reform status: Bill C-36, the government's PIPEDA replacement, was tabled on June 15, 2026 and the page still said no bill existed; and Bill C-15's federal data-portability provisions, which the page said were in force, received Royal Assent on March 26, 2026 but await an order in council, so no federal portability right exists yet. Also corrected the Quebec biometric filing rule (it sits in the IT framework Act, and the 60-day lead time applies to creating a biometric database), the mandatory privacy impact assessment trigger, the scope of the Law 25 portability right, the basis of the CAI's facial-recognition order, and the OPC's OpenAI findings on consent and appropriate purposes.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Independently fact-checked against the cited primary sources

Major refresh: expanded from ~2,850 to ~5,500 words. Added Recent Enforcement Highlights section (OpenAI ChatGPT joint investigation May 2026, Google delist finding Aug 2025, CAI biometric order). Updated Bill C-15 status to passed (Royal Assent, March 26, 2026); the PIPEDA data mobility provisions are enacted but not in force pending an order in council. Expanded 45th Parliament reform outlook including Carney government priorities and potential 5% revenue penalty threshold. Expanded Alberta PIPA section with Standing Committee 12 recommendations (Feb 2025) and Spring 2026 public consultation. Added Appropriate Purposes Test section (PIPEDA s. 5(3)). Added Business Compliance Checklist section. Expanded FAQ from 5 to 10 pairs. Updated comparison table data portability row. Corrected individual penalties under Quebec Law 25 (admin cap $50,000 for individuals; penal cap $100,000 for individuals). Title and meta unchanged -- existing CTR metrics acceptable.

Reviewed and approved by an editor

Sources and References

  1. Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5(laws-lois.justice.gc.ca).gov
  2. PIPEDA Fair Information Principles -- Schedule 1(priv.gc.ca).gov
  3. OPC Guidelines for Obtaining Meaningful Consent(priv.gc.ca).gov
  4. Privacy Act, RSC 1985, c P-21 -- Full Text(laws-lois.justice.gc.ca).gov
  5. Canada's Privacy Act -- Department of Justice Overview(justice.gc.ca).gov
  6. Act respecting the protection of personal information in the private sector, CQLR c P-39.1 (Quebec Law 25)(legisquebec.gouv.qc.ca).gov
  7. Commission d'acces a l'information du Quebec (CAI)(cai.gouv.qc.ca).gov
  8. Osler -- Law 25 Enforcement Scheme for Protection of Personal Information in Quebec(osler.com)
  9. Osler -- Quebec Privacy Commissioner Sets High Bar for Biometric Data Processing(osler.com)
  10. Alberta Personal Information Protection Act (PIPA) -- Overview(alberta.ca).gov
  11. OPC Issue Sheets -- Review of Alberta PIPA (September 2024)(priv.gc.ca).gov
  12. British Columbia Personal Information Protection Act (PIPA) -- Full Text(bclaws.gov.bc.ca).gov
  13. Provincial Laws Deemed Substantially Similar to PIPEDA -- OPC(priv.gc.ca).gov
  14. Mandatory Breach Reporting Under PIPEDA -- OPC Guidance (SOR/2018-64)(priv.gc.ca).gov
  15. OPC Guidelines for Cross-Border Data Transfers(priv.gc.ca).gov
  16. European Commission Adequacy Decision Renewal -- Canada (January 15, 2024)(ec.europa.eu).gov
  17. Bill C-27 (44th Parliament, 1st Session) -- LEGISinfo(parl.ca).gov
  18. Fasken -- Prorogation's Digital Impact: Canada's Digital Bills Die on the Order Paper (January 2025)(fasken.com)
  19. IAPP -- What 2026 May Bring for Canada's Privacy Reform Efforts(iapp.org)
  20. Bill C-15 (45th Parliament, 1st Session) -- Budget 2025 Implementation Act, No. 1, SC 2026, c. 3 (Royal Assent, March 26, 2026)(parl.ca).gov
  21. OPC Statement on Bill C-15 to House of Commons Standing Committee (January 2026)(priv.gc.ca).gov
  22. OPC 2024-25 Annual Report -- Prioritizing Privacy in a Data-Driven World(priv.gc.ca).gov
  23. PIPEDA Findings #2026-002 -- Joint Investigation of OpenAI OpCo, LLC (May 2026)(priv.gc.ca).gov
  24. PIPEDA Findings #2025-002 -- Google Search Engine / Right to Delist (August 27, 2025)(priv.gc.ca).gov
  25. OPC Compliance Agreement -- World Anti-Doping Agency (2026)(priv.gc.ca).gov
  26. Osler -- Canada's 2026 Privacy Priorities: Data Sovereignty, Open Banking and AI(osler.com)
Share: