Canada
Canada Data Privacy Laws: PIPEDA & Provincial Guide (2026)
Independently fact-checked against primary sources (last audited September 9, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 9, 2026. · 21 primary sources cited on this page. How we verify our legal content

Canada's data privacy framework centers on PIPEDA (SC 2000, c 5) for federal private-sector and cross-border activity, with Quebec Law 25, Alberta PIPA (SA 2003, c P-6.5), and BC PIPA (SBC 2003, c 63) applying within their respective provinces, each enforced by a separate regulator with its own penalty structure.
Canada's approach to data privacy is deliberately layered: federal legislation, provincial statutes, and sector-specific rules operate simultaneously, and organizations must navigate whichever combination applies to their activities and geography. Unlike jurisdictions with a single comprehensive data protection law, Canada requires compliance officers to identify which of several parallel regimes governs each category of data they handle.
This guide covers the complete Canadian privacy landscape as it stands in September 2026, from the federal PIPEDA framework and Quebec's GDPR-comparable Law 25, to recent landmark enforcement decisions, the death of Bill C-27, the passage of Bill C-15, and Bill C-36, the PIPEDA replacement now before the House of Commons.
For Canadian laws on audio and video recording consent, see our companion article on Canada recording laws.
Jurisdiction scope: This article addresses Canada's federal private-sector privacy law (PIPEDA, SC 2000, c 5), the federal public-sector Privacy Act (RSC 1985, c P-21), the provincial private-sector statutes in Quebec, Alberta, and British Columbia, and recent federal legislative developments. It does not address provincial health information acts (PHIPA, HIA, etc.) or sector-specific federal privacy regimes (PIPEDA financial sector rules under the Bank Act). Statutes cited reflect their in-force versions as of September 9, 2026.
Quick Answer: Which Privacy Law Applies to You?
Canadian privacy law does not follow a single statute. Whether PIPEDA or a provincial equivalent governs your organization depends on two factors: what sector you operate in, and where your data-handling activity takes place.
Federal PIPEDA applies to every private-sector organization that collects, uses, or discloses personal information in the course of commercial activity across provincial or national borders, plus all federally regulated industries (banking, telecommunications, interprovincial transportation, broadcasting) regardless of province.
Quebec's Law 25 applies instead of PIPEDA for private-sector intra-provincial activity in Quebec. PIPEDA still applies to federally regulated entities and cross-border transfers even in Quebec.
Alberta's PIPA and BC's PIPA apply instead of PIPEDA for private-sector intra-provincial activity in those provinces. PIPEDA still governs federally regulated sectors and cross-provincial data flows.
The federal Privacy Act governs the approximately 265 federal government institutions: departments, agencies, Crown corporations, and agents of Parliament. It does not apply to private-sector entities.
All other provinces and territories have no substantially similar private-sector law; PIPEDA governs by default.

PIPEDA: Canada's Federal Private-Sector Privacy Law
The Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5, has governed Canada's private sector since it took full effect in 2004. PIPEDA applies to the collection, use, and disclosure of personal information in the course of commercial activity. It defines "personal information" broadly as any information about an identifiable individual (s. 2(1)), a definition courts and the OPC have interpreted to capture not only names and contact details but also IP addresses, device identifiers, and behavioural profiles.
PIPEDA covers every private-sector organization handling personal information as part of commercial activity in Canada, including businesses operating across provincial borders, all federally regulated industries, and any organization transferring personal information across provincial or national borders for processing. It does not apply to provincial or federal government institutions.
The 10 Fair Information Principles
PIPEDA is built on 10 Fair Information Principles set out in Schedule 1 of the Act. These principles form the backbone of every compliance obligation under the law:
-
Accountability. An organization is responsible for personal information under its control. It must designate a privacy officer and remain accountable for data transferred to third-party processors through contractual or other means.
-
Identifying Purposes. The purposes for collecting personal information must be identified at or before the time of collection.
-
Consent. The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except in specific circumstances defined by the Act.
-
Limiting Collection. The collection of personal information must be limited to what is necessary for the identified purposes.
-
Limiting Use, Disclosure, and Retention. Personal information must not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law. It must be retained only as long as necessary.
-
Accuracy. Personal information must be as accurate, complete, and up to date as necessary for the purposes for which it is to be used.
-
Safeguards. Personal information must be protected by security safeguards appropriate to the sensitivity of the information.
-
Openness. An organization must make its policies and practices regarding the management of personal information readily available to individuals.
-
Individual Access. Upon request, an individual must be informed of the existence, use, and disclosure of their personal information and be given access to that information, with the right to challenge its accuracy.
-
Challenging Compliance. An individual must be able to challenge an organization's compliance with these principles by contacting the designated privacy officer or the Office of the Privacy Commissioner of Canada.
The Appropriate Purposes Test (PIPEDA s. 5(3))
Section 5(3) of PIPEDA establishes a separate, foundational obligation that operates alongside the 10 Principles: an organization may collect, use, or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances. This is the "appropriate purposes" test.
The test is not the same as consent. Even where an individual has given consent, collection or use for an inappropriate purpose violates s. 5(3). The OPC has applied this test in numerous investigations to strike down purposes that, while technically consented to, were found to be disproportionate to the legitimate organizational need.
The appropriate-purposes test gained new prominence in May 2026 when the OPC and three provincial regulators applied it in their joint investigation of OpenAI's ChatGPT. The regulators accepted that OpenAI's purposes for developing and deploying ChatGPT are appropriate. They nonetheless found that the manner in which OpenAI initially collected personal information from internet sources and third parties to train its GPT-3.5 and 4 models, together with the scale and nature of that collection, was overbroad and therefore inappropriate under s. 5(3). The finding establishes that "publicly available" information online does not, under PIPEDA, automatically become available for commercial AI training.
Consent Framework Under PIPEDA
Consent under PIPEDA must be meaningful. Organizations must explain in plain language what personal information they collect, why they collect it, and how it will be used or disclosed. The OPC's guidelines require consent to be:
- Informed. Individuals must understand what they are agreeing to.
- Voluntary. Consent cannot be bundled as a condition of service unless the information is genuinely required to provide that service.
- Specific. Blanket consent covering unlimited future uses is not valid.
Consent can be express (written or oral affirmation) or implied (where the purpose would be obvious to a reasonable person), depending on the sensitivity of the information and the reasonable expectations of the individual. Sensitive information, such as health records, financial data, or information about minors, almost always requires express consent.
Individuals have the right to withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice from the organization about the implications of withdrawal.
The Office of the Privacy Commissioner of Canada
The Office of the Privacy Commissioner of Canada (OPC) is the federal body responsible for overseeing compliance with both PIPEDA and the Privacy Act. The Privacy Commissioner is an independent Officer of Parliament.
The OPC's enforcement powers under PIPEDA include:
- Investigating complaints filed by individuals about organizational practices.
- Initiating investigations on its own where there are reasonable grounds.
- Conducting audits of organizational privacy practices.
- Issuing reports of findings with recommendations.
- Entering into compliance agreements with organizations.
- Applying to the Federal Court for an order to enforce recommendations.
A significant limitation of the OPC's current authority is that it cannot directly impose fines. For criminal penalties under PIPEDA, the OPC must refer matters to the Attorney General of Canada, who may direct the Director of Public Prosecutions to initiate proceedings. This enforcement gap has been a central argument for legislative reform.
In January 2025 the Privacy Commissioner unveiled a transformation plan that re-frames the OPC's compliance function as a continuum, combining proactive engagement and formal investigative functions into one sector. The 2024-25 Annual Report says the restructuring comes into full effect over 2025-2026.
Bill C-27: Why Canada's Privacy Reform Failed
Bill C-27, the Digital Charter Implementation Act, 2022, was introduced in June 2022 as the most ambitious overhaul of Canada's privacy framework in two decades. It contained three parts:
- The Consumer Privacy Protection Act (CPPA): Would have replaced PIPEDA Part 1, introducing administrative monetary penalties up to 3% of global revenue or CAD $10 million, direct order-making powers for the Privacy Commissioner, and a private right of action.
- The Personal Information and Data Protection Tribunal Act: Would have created an independent tribunal to hear appeals and impose the new penalties.
- The Artificial Intelligence and Data Act (AIDA): Canada's first legislative attempt to regulate high-impact AI systems.
After three years of committee study, including a detailed clause-by-clause review in the Standing Committee on Industry and Technology, Bill C-27 died on the Order Paper on January 6, 2025, when the Governor General prorogued Parliament on the advice of Prime Minister Trudeau following his announced resignation. Nearly three years of amendments and stakeholder consultation were lost.
The prevailing view among commentators is that bundling AI regulation with privacy reform slowed both files. The proposed tribunal model also attracted substantial criticism as an unnecessary layer between the OPC and enforcement. These lessons are expected to shape the architecture of the replacement legislation.
Current status as of September 2026: PIPEDA remains in force. The replacement bill, C-36, was tabled on June 15, 2026 and is at second reading in the House of Commons, so it is not law. Bill C-15 added a data mobility framework to PIPEDA, but those provisions are not yet in force (see below).
What Replaced It: Bill C-36, the Proposed PIPEDA Replacement
On June 15, 2026 the government tabled Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts. It was sponsored by the Minister of Artificial Intelligence and Digital Innovation and is at second reading in the House of Commons.
Bill C-36 is a bill, not a law. Nothing in it applies to any organization yet.
Its main elements, read from the bill text:
A standalone private-sector statute. Part 1 would enact the Protecting Privacy and Consumer Data Act, repeal Part 1 of PIPEDA, and rename what remains of PIPEDA the Electronic Documents Act.
A commission in place of the C-27 tribunal. The Privacy Commissioner would investigate complaints and serve a notice of contravention setting out the penalty and any proposed order (s. 107). An organization could apply for review to the Digital Safety and Data Protection Commission of Canada, which decides the matter and makes the order (ss. 109 and 110). That Commission would be created by Bill C-34, the Safe Social Media Act, which is also still at second reading, and C-36 cannot come into force before it does.
Administrative penalties. The maximum penalty for all contraventions found in any one investigation is the greater of $10 million and 3% of the organization's gross global revenue (s. 114). No penalty may be imposed where the organization proves due diligence, or where it complied with an approved certification program covering the provision at issue (s. 113(3)).
Separate offence fines. Knowingly breaching the breach-reporting, record-keeping, whistleblower or order provisions, or obstructing the Commissioner or the Commission, carries a fine of up to the greater of $25 million and 5% of gross global revenue on indictment, or the greater of $20 million and 4% on summary conviction (s. 145).
A private right of action. An individual could sue for damages for loss or injury caused by a contravention, within two years of becoming aware of the finding or conviction (s. 132).
No AI chapter. The Artificial Intelligence and Data Act that was bundled into C-27 is not part of C-36, confirming the split that commentators expected after C-27 failed. Those commentators also expected a headline penalty of 5% of gross global revenue; the bill puts 3% on the administrative track and reserves the 5% figure for indictable offences.
Bill C-36 would come into force on a day or days fixed by order of the Governor in Council (s. 52). Its coordinating amendments would repeal Bill C-15's data mobility Division if C-36's replacement Part comes into force first.
Until Bill C-36 passes and is brought into force, PIPEDA governs private-sector activity and organizations must comply with its existing requirements.
Bill C-15: Federal Data Mobility Enacted but Not Yet in Force
Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent on March 26, 2026 and is now SC 2026, c. 3. Part 5, Division 23 of that Act (ss. 389 to 398) adds a new Division 1.2, Mobility of Personal Information, to PIPEDA.
Under the new s. 10.4, an organization would have to disclose, on an individual's request and as soon as feasible, the personal information it collected from that individual to an organization the individual designates, subject to the regulations and only if both organizations are subject to a data mobility framework. Sections 10.5 and 10.6 let the Governor in Council, after consulting the OPC, make those regulations, prescribe safeguards and interoperability parameters, and specify which organizations are covered. The OPC testified before the Standing Committee on Industry and Technology in January 2026 supporting the framework while recommending robust regulatory safeguards.
None of it is in force. Section 398 provides that the Division comes into force on a day to be fixed by order of the Governor in Council. No such order has been made, no data mobility framework has been prescribed, and the consolidated PIPEDA on the Justice Laws website still lists s. 389 under Amendments Not in Force. There is no federal data portability right today.
Quebec Law 25: North America's Strongest Privacy Regime
Quebec Law 25 (originally Bill 64, formally known as An Act to modernize legislative provisions as regards the protection of personal information) amended the Act respecting the protection of personal information in the private sector (CQLR c P-39.1) and the public-sector access act. Adopted in 2021, its provisions took effect in three phases: September 2022, September 2023, and September 2024. All provisions are now fully in force.
The result is a privacy regime frequently compared to the EU's GDPR in scope and severity. It is enforced by the Commission d'accès à l'information du Québec (CAI).
Key Provisions of Law 25
Privacy Officer Requirement. Every organization must designate a person responsible for the protection of personal information. By default, this role falls to the person with the highest authority within the enterprise.
Privacy Impact Assessments (PIAs). Section 3.3 requires a PIA for any project to acquire, develop or overhaul an information system or electronic service delivery system that involves collecting, using, communicating, keeping or destroying personal information. Section 17 requires one before communicating personal information outside Quebec, including where an outside-Quebec provider is entrusted with it. Engaging a service provider inside Quebec does not trigger a PIA: s. 18.3 requires a written mandate or contract specifying the confidentiality measures the provider must take.
Mandatory Cookie Consent. Quebec is the only North American jurisdiction requiring explicit opt-in consent for tracking technologies including cookies, comparable to the GDPR. Organizations must obtain clear, free, and informed consent before deploying any technology that collects personal information through tracking.
Biometric Data. The biometric filing rules sit in the Act to establish a legal framework for information technology (CQLR c C-1.1), as amended by Law 25, not in P-39.1. Under s. 45, creating a database of biometric characteristics must be disclosed to the CAI promptly and no later than 60 days before it is brought into service. Under s. 44, verifying or confirming identity by biometric means requires prior disclosure to the CAI, with no fixed lead time, plus the express consent of the person concerned, and only the minimum characteristics needed may be used. The CAI reads these provisions to require a non-biometric alternative for identity verification.
Data Portability. Since September 22, 2024, s. 27 entitles an individual to receive computerized personal information collected from them, excluding information the enterprise created or inferred, in a structured and commonly used technological format, unless doing so raises serious practical difficulties. On request that information must also be communicated to any person or body authorized by law to collect it, which is narrower than a transfer to any organization the individual picks.
Anonymization. Law 25 permits anonymization as an alternative to destruction of personal information, but only according to generally recognized best practices and criteria set by government regulation.
Sensitive Personal Information. The law establishes a category of sensitive information, including health data, biometrics, and information with a strong expectation of privacy, that attracts heightened obligations.
Quebec Law 25 Penalties
Law 25 introduced a two-tier penalty structure:
Administrative monetary penalties: Up to CAD $10 million or 2% of the enterprise's worldwide turnover for the preceding fiscal year, whichever is greater. For individuals, the cap is CAD $50,000.
Penal fines: Up to CAD $25 million or 4% of worldwide turnover, whichever is greater. For individuals, the penal cap is CAD $100,000. The CAI can initiate penal proceedings within five years of the commission of an offence.
Law 25 also created a private right of action. Individuals may claim punitive damages of at least CAD $1,000 for intentional or grossly negligent interference with their privacy rights.
CAI Enforcement: First Actions Under Law 25
In September 2024 the oversight division of the CAI issued its first decision since Law 25 came fully into force, following a self-initiated investigation into biometric practices at a Quebec printing company. The employer had declared the creation of its biometric database to the CAI and had obtained employee consent, as Quebec law requires. It lost anyway.
The CAI applied the necessity and proportionality test. It found the employer could not show that using facial recognition for access control served a real or important objective, and that the invasion of employee privacy was neither sufficiently minimized nor clearly outweighed by the benefits. The CAI ordered the company to stop collecting facial biometric data, stop using the system for access control, and destroy the data already collected. No monetary penalty was imposed, so this was an order from the oversight division rather than a decision under the administrative penalty regime. Osler's commentary sets out the test in detail.
The compliance lesson runs the opposite way from what many organizations assume. Filing the biometric declaration and collecting consent does not make a biometric system lawful in Quebec if the collection fails necessity and proportionality.
Alberta and British Columbia: Provincial PIPAs
Alberta and British Columbia each enacted their own Personal Information Protection Acts (PIPA), both declared substantially similar to PIPEDA by the Governor in Council. When a provincial law is deemed substantially similar, it displaces PIPEDA for intra-provincial private-sector activity in that province. PIPEDA continues to apply to federally regulated organizations and to cross-border data transfers.
Alberta PIPA
Alberta's PIPA (SA 2003, c P-6.5) has been in effect since 2004. It applies to private-sector organizations collecting, using, or disclosing personal information in Alberta. The Office of the Information and Privacy Commissioner of Alberta (OIPC-AB) oversees compliance.
Alberta's PIPA reform is advancing more quickly than the federal file. The Standing Committee on Resource Stewardship completed its statutory review and issued a Final Report on February 21, 2025, containing 12 recommendations including:
- Specific provisions governing the collection, use, and disclosure of minors' personal information.
- Authority for the OIPC-AB to impose administrative monetary penalties, with clear criteria and an appeal mechanism.
- Updated requirements to address emerging technologies and alignment with evolving federal and global standards.
In Spring 2026 the Alberta government is continuing its PIPA modernization engagement, meeting with the OIPC-AB; the public online survey ran from February 2 to February 17, 2026 and the results are under review. No amendment bill has been introduced. PIPA has not undergone major revision since 2010; the current reform process is expected to produce a modernized Act over the next legislative cycle.
British Columbia PIPA
British Columbia's PIPA (SBC 2003, c 63) governs private-sector personal information handling within BC. The Office of the Information and Privacy Commissioner for BC (OIPC-BC) oversees the Act.
A Special Committee of the Legislative Assembly completed a comprehensive review and published 34 recommendations in December 2021 to modernize BC's PIPA. Key recommendations included: introducing meaningful consent, mandatory breach notification, enhanced OIPC-BC audit and enforcement powers including administrative monetary penalties, and alignment with GDPR standards. As of 2026, the BC government has not formally responded to the report or introduced amending legislation.
Both provincial PIPAs share PIPEDA's core principles around consent, purpose limitation, and individual access rights. The practical differences for organizations lie in which regulator they report to, which specific procedural requirements apply, and the pace of reform in each jurisdiction.
Mandatory Breach Notification Under PIPEDA
Since November 1, 2018, organizations subject to PIPEDA must comply with mandatory breach notification requirements established by the Breach of Security Safeguards Regulations (SOR/2018-64).
When a breach of security safeguards occurs involving personal information under an organization's control, the organization must:
-
Assess the breach. Determine whether it creates a real risk of significant harm (RROSH) to any individual. Factors include the sensitivity of the information, the probability that it has been or will be misused, and the potential consequences for affected individuals.
-
Report to the OPC. If the breach poses a RROSH, the organization must report it to the Privacy Commissioner as soon as feasible using the prescribed form.
-
Notify affected individuals. Notification must be given directly to affected individuals as soon as feasible, describing the breach, the information involved, steps the organization is taking, and steps the individual can take to reduce risk of harm.
-
Notify third-party organizations. If another organization or government institution could reduce the risk of harm, they must also be notified.
-
Maintain records. Organizations must keep a record of every breach of security safeguards, whether or not it triggered reporting, for a minimum of 24 months. The OPC can request access to these records at any time.
Organizations that knowingly fail to report, notify, or maintain breach records face fines of up to CAD $100,000 per offence under PIPEDA s. 28.
PIPEDA Penalties and Enforcement
PIPEDA's penalty framework is modest compared to Quebec's Law 25 or the EU's GDPR, and this gap is the primary driver of the reform agenda:
Summary conviction: Fines up to CAD $10,000 per offence.
Indictable offence: Fines up to CAD $100,000 per offence.
These penalties apply under s. 28 of PIPEDA for knowingly violating breach notification requirements, obstructing the Privacy Commissioner during an investigation, or contravening specific provisions of the Act.
The OPC does not directly issue fines. Enforcement depends on referral to the Attorney General and prosecution by the Director of Public Prosecutions, a process that has been used rarely. Organizations found to have violated PIPEDA may face Federal Court orders requiring correction of practices, publication of notice of actions taken, and payment of damages to complainants including damages for humiliation.
Individual Rights Under Canadian Privacy Law
Canadians have a core set of privacy rights that vary in mechanism by applicable law:
Right to Access. Individuals can request access to any personal information an organization holds about them. Organizations must respond within 30 calendar days under PIPEDA, at minimal or no cost.
Right to Correction. If personal information is inaccurate or incomplete, individuals can request amendments. Where the organization disagrees, the individual's objection must be recorded.
Right to Withdraw Consent. Individuals can withdraw consent for the collection, use, or disclosure of their personal information at any time, subject to reasonable notice and legal or contractual restrictions.
Right to Complain. Individuals can file complaints with the OPC (for PIPEDA matters), the relevant provincial commissioner, or the CAI in Quebec.
Right to Data Portability. Available under Quebec Law 25 since September 22, 2024, within the limits s. 27 of that Act sets. Federally, Bill C-15 added a data mobility framework to PIPEDA on Royal Assent (March 26, 2026), but that Division is not in force and no regulations have been made, so there is no federal portability right today.
Right to De-indexing. Quebec Law 25 provides a right to de-indexing. PIPEDA does not provide an explicit GDPR-style right to erasure, though the OPC's Google delist finding (PIPEDA Findings #2025-002, August 27, 2025) confirmed a limited right to delist under PIPEDA in circumstances where a reasonable person would find it inappropriate for a search engine to continue returning personal information.
Cross-Border Data Transfers
PIPEDA does not prohibit cross-border transfers of personal information. Instead, it relies on the accountability principle: the transferring organization remains responsible for the protection of personal information regardless of where it is processed.
Organizations must:
- Use contractual or other means to ensure the recipient provides a comparable level of protection.
- Be transparent with individuals about the possibility that their data may be processed in another jurisdiction.
- Assess the risks that foreign laws (including national security and law enforcement access laws) could affect the integrity, security, or confidentiality of the data.
No contract can override the laws of the receiving country. Organizations must weigh the practical reality that transferring data to a jurisdiction with weaker protections or broad government access powers creates residual risk.
Quebec Law 25 imposes stricter requirements, mandating a Privacy Impact Assessment before any transfer of personal information outside the province.
EU Adequacy for Canada
The European Commission renewed Canada's adequacy status on January 15, 2024, confirming that PIPEDA provides a level of protection essentially equivalent to the EU's GDPR. This allows personal data to flow from the EU to PIPEDA-covered Canadian organizations without standard contractual clauses or other supplementary safeguards.
The adequacy finding applies only to commercial organizations subject to PIPEDA. It does not cover:
- Canadian government institutions (governed by the Privacy Act).
- Organizations in provinces where a substantially similar provincial law applies (Quebec, Alberta, BC) -- those transfers remain covered for organizations subject to federal PIPEDA jurisdiction, but provincial law may require independent analysis.
In its renewal decision, the European Commission explicitly noted that some protections developed at sub-legislative level (through OPC guidelines and practices) should be enshrined in statute to enhance legal certainty, and called on Canada to advance legislative reform. The Commission's next four-year review will take place in or around 2028.
Recent Enforcement Highlights
OpenAI ChatGPT: Joint Investigation (May 2026)
On May 6, 2026, the OPC, the CAI, the OIPC-BC, and the OIPC-AB jointly released PIPEDA Findings #2026-002, the results of a multi-year investigation into OpenAI's compliance with federal and provincial privacy legislation in relation to ChatGPT.
Key findings:
- Scraping personal information from the internet does not constitute collection of "publicly available" information exempt from PIPEDA or the provincial PIPAs.
- Developing and deploying ChatGPT is an appropriate purpose, but the manner in which OpenAI initially collected personal information from internet sources and third parties to train GPT-3.5 and 4, and the scale and nature of that collection, was overbroad and therefore inappropriate under PIPEDA s. 5(3).
- On consent, the OPC accepted that OpenAI may rely on implied consent for scraped and licensed data where the risk to privacy is significantly and meaningfully mitigated, and accepted implied consent for fine-tuning future models on a subset of user interactions.
- The OPC found the matter well-founded and conditionally resolved under PIPEDA. The OIPC-BC and OIPC-AB found the consent issue well-founded and unresolved, concluding that OpenAI's models are based on scraped data for which consent has not been and cannot be obtained under PIPA-BC and PIPA-AB where training is done in the same manner as for GPT-3.5 and 4. Both offices expressly declined to rule on future models.
- The CAI found the appropriate-purposes, individual-rights and accountability issues well-founded and conditionally resolved, and the consent and retention issues well-founded and unresolved.
The finding is the most significant Canadian privacy enforcement action involving AI to date.
Google Search: Right to Delist (August 2025)
In PIPEDA Findings #2025-002 (August 27, 2025), the OPC investigated whether Google contravened PIPEDA by returning links to outdated and misleading articles about an individual when their name was searched. The OPC found there are limited circumstances in which a reasonable person would consider it inappropriate for a search engine to return personal information, and confirmed a right to delist under PIPEDA. The decision establishes a Canadian analogue to the EU's "right to be forgotten," though with a narrower scope.
CAI Biometric Enforcement (September 2024)
In its first decision since Law 25 came fully into force, the CAI ordered a Quebec printing company to stop using facial recognition for employee access control. The company had declared its biometric database to the CAI and obtained employee consent; the order rested on the necessity and proportionality test, not on any notification or consent failure. No monetary penalty was imposed.
World Anti-Doping Agency: Compliance Agreement (2026)
The OPC reached a compliance agreement with the World Anti-Doping Agency in 2026, resolving an investigation into WADA's handling of personal information. The agreement reflects the OPC's increasing willingness to use compliance agreements as an alternative to Federal Court proceedings.
Loblaw PC Optimum Program (2026)
PIPEDA Findings #2026-001 (March 5, 2026) involved an investigation into Loblaw's personal information retention practices for the PC Optimum loyalty program, reflecting continued OPC attention to retail sector data handling.
X Corp. and X.AI: Sexualized Deepfakes (June 2026)
In PIPEDA Findings #2026-004 (June 11, 2026), the OPC reported on Commissioner-initiated complaints against X Corp. and X.AI LLC, opened on January 15, 2026 after reports that the Grok chatbot had generated and publicly disclosed sexually explicit deepfakes of real, identifiable people. The OPC found the companies had not obtained valid consent to collect, use and disclose personal information for that purpose, that a reasonable person would consider the practice inappropriate, and that their response to the problem was insufficient.
TikTok: Joint Investigation (September 2025)
In PIPEDA Findings #2025-003 (September 23, 2025), the OPC, the CAI, the OIPC-BC and the OIPC-AB jointly reported on TikTok's collection and use of personal information, focusing on underage users and on whether TikTok obtained meaningful consent for tracking, profiling and content personalization. It is the four-regulator template the OpenAI investigation followed.
Comparison: PIPEDA vs. Quebec Law 25
| Feature | PIPEDA | Quebec Law 25 |
|---|---|---|
| Maximum penalty (organizations) | $100,000 | $25 million or 4% of revenue |
| Maximum penalty (individuals) | $100,000 | $100,000 (penal) |
| Breach notification | Mandatory since 2018 | Mandatory |
| Cookie consent | Not explicitly required | Mandatory opt-in |
| Privacy impact assessments | Recommended | Mandatory |
| Private right of action | Limited (Federal Court) | Yes, minimum $1,000 punitive damages |
| Data portability | Enacted (Bill C-15, 2026) but not in force | Yes (since September 22, 2024), for information collected from the individual |
| Biometric disclosure | Not required | Prior disclosure to CAI; 60 days before a biometric database goes into service |
| Regulator can fine directly | No | Yes |
| AI scraping guidance | OPC finding #2026-002 | CAI joint finding #2026-002 |
Business Compliance Checklist
Organizations operating in Canada should verify the following obligations depending on which law applies:
Under PIPEDA:
- Designate a privacy officer accountable for compliance.
- Identify purposes for every category of personal information collected, at or before collection.
- Obtain meaningful consent (express for sensitive information; implied where purpose would be obvious and information is not sensitive).
- Limit collection to what is necessary for identified purposes.
- Implement security safeguards appropriate to information sensitivity.
- Post a publicly accessible privacy policy.
- Respond to access requests within 30 days.
- Assess every security incident for real risk of significant harm; report RROSH breaches to the OPC and affected individuals as soon as feasible.
- Maintain records of all security incidents for 24 months.
Additional obligations under Quebec Law 25:
- Conduct a Privacy Impact Assessment before any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information (s. 3.3).
- Conduct a PIA before communicating personal information outside Quebec, including to an outside-Quebec service provider (s. 17).
- For a service provider inside Quebec, put the mandate or contract in writing and specify the confidentiality measures it must take (s. 18.3). That alone needs no PIA.
- Obtain express opt-in consent before deploying tracking technologies (cookies, pixels, etc.).
- Disclose the creation of a biometric database to the CAI at least 60 days before it goes into service, and disclose biometric identity verification to the CAI before use, with express consent (C-1.1, ss. 44 and 45).
- Honour s. 27 requests: give the individual the computerized information collected from them in a structured, commonly used format, and send it to a person or body authorized by law to collect it if they ask.
Additional considerations for Alberta and BC:
- Report RROSH breaches to the relevant provincial commissioner (OIPC-AB or OIPC-BC) rather than the OPC for intra-provincial activity.
- Monitor provincial reform developments: Alberta is in active consultation; BC amendments remain pending.
Watch out: Organizations operating in multiple provinces must often comply with multiple regimes simultaneously. A national retailer with customers in Quebec, Alberta, BC, and Ontario must comply with Law 25 for Quebec customers, Alberta PIPA and BC PIPA for customers in those provinces, and PIPEDA for customers elsewhere. Cross-border transfers to the US trigger PIPEDA accountability obligations even where provincial law applies to in-province collection.
The Privacy Act: Federal Public Sector
The Privacy Act (RSC 1985, c P-21) covers the approximately 265 federal government institutions. Federal institutions may only collect personal information directly related to an operating program or activity, and may only use or disclose it for the purpose for which it was collected or a consistent purpose, absent consent.
Individuals have the right to access their personal information held by government institutions, request corrections to inaccurate information, and file complaints with the Privacy Commissioner about government handling of their data.
The Privacy Act has not been significantly updated since 1983. It lacks mandatory breach notification for government institutions and meaningful enforcement mechanisms comparable to PIPEDA's. Bill C-36 does not modernize it: the bill touches the Privacy Act only to rename a body listed in its schedule. The Privacy Commissioner's 2024-25 Annual Report called for modernization of the Privacy Act to proceed in parallel with private-sector reform.
Disclaimer
This article presents general legal information about Canadian data privacy laws. It does not constitute legal advice and does not create a solicitor-client relationship. The laws described -- including PIPEDA (SC 2000, c 5), the Privacy Act (RSC 1985, c P-21), Quebec Law 25 (CQLR c P-39.1), Alberta PIPA (SA 2003, c P-6.5), and BC PIPA (SBC 2003, c 63) -- are presented as of their in-force versions on September 9, 2026. Laws change; readers should verify current requirements before relying on any information in this article. Organizations with compliance obligations under Canadian privacy law should consult a lawyer licensed in the relevant Canadian jurisdiction for advice on their specific situation.
Authorities Cited
- Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5. https://laws-lois.justice.gc.ca/eng/acts/p-8.6/
- PIPEDA Fair Information Principles -- Schedule 1. Office of the Privacy Commissioner of Canada. https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/p_principle/
- OPC Guidelines for Obtaining Meaningful Consent (2018). https://www.priv.gc.ca/en/privacy-topics/collecting-personal-information/consent/gl_omc_201805/
- Privacy Act, RSC 1985, c P-21. https://laws-lois.justice.gc.ca/eng/acts/p-21/fulltext.html
- Department of Justice Canada -- Privacy Act overview. https://www.justice.gc.ca/eng/csj-sjc/pa-lprp/pa-lprp.html
- Act respecting the protection of personal information in the private sector, CQLR c P-39.1, as amended by Law 25 (2021). https://www.legisquebec.gouv.qc.ca/en/document/cs/p-39.1
- Commission d'accès à l'information du Québec (CAI). https://www.cai.gouv.qc.ca/english
- Osler -- Law 25 enforcement scheme for protection of personal information in Quebec. https://www.osler.com/en/insights/updates/law-25-a-new-enforcement-scheme-for-protection-of-personal-information-in-the-private-sector-in-que/
- Osler -- Quebec privacy commissioner sets high bar for biometric data processing (2025). https://www.osler.com/en/insights/updates/high-bar-for-biometric-data-processing/
- Personal Information Protection Act (Alberta), SA 2003, c P-6.5. https://www.alberta.ca/personal-information-protection-act
- OPC Issue Sheets -- Review of Alberta PIPA (September 2024). https://www.priv.gc.ca/en/privacy-and-transparency-at-the-opc/proactive-disclosure/opc-parl-bp/ab_20240924/is_ab_20240924/
- Personal Information Protection Act (BC), SBC 2003, c 63. https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
- OPC -- Provincial Laws Deemed Substantially Similar to PIPEDA. https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/prov-pipeda/
- Breach of Security Safeguards Regulations, SOR/2018-64. https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/
- OPC Guidelines for Cross-Border Data Transfers. https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/
- European Commission adequacy decision renewal -- Canada (January 15, 2024). https://ec.europa.eu/commission/presscorner/detail/en/ip_24_161
- Bill C-27 (44th Parliament, 1st Session) -- LEGISinfo. https://www.parl.ca/legisinfo/en/bill/44-1/c-27
- Fasken -- Prorogation's Digital Impact: Canada's Digital Bills Die on the Order Paper (January 2025). https://www.fasken.com/en/knowledge/2025/01/prorogations-digital-impact
- IAPP -- What 2026 May Bring for Canada's Privacy Reform Efforts. https://iapp.org/news/a/what-2026-may-bring-for-canadas-privacy-reform-efforts
- Bill C-15 (45th Parliament, 1st Session) -- Budget 2025 Implementation Act, No. 1, SC 2026, c. 3 (Royal Assent, March 26, 2026). https://www.parl.ca/DocumentViewer/en/45-1/bill/C-15/royal-assent
- OPC -- Statement on Bill C-15 to House of Commons Standing Committee on Industry and Technology (January 2026). https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2026/parl_260126/
- OPC 2024-25 Annual Report -- Prioritizing Privacy in a Data-Driven World. https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202425/ar_202425/
- PIPEDA Findings #2026-002 -- Joint Investigation of OpenAI OpCo, LLC. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/
- PIPEDA Findings #2025-002 -- Google Search Engine / Right to Delist (August 27, 2025). https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2025/pipeda-2025-002/
- OPC Compliance Agreement -- World Anti-Doping Agency (2026). https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/2026-wada-ca/
- Osler -- Canada's 2026 Privacy Priorities: Data Sovereignty, Open Banking and AI. https://www.osler.com/en/insights/reports/2025-legal-outlook/canadas-2026-privacy-priorities-data-sovereignty-open-banking-and-ai/
- Bill C-36 (45th Parliament, 1st Session) -- An Act to enact the Protecting Privacy and Consumer Data Act (first reading, June 15, 2026). https://www.parl.ca/legisinfo/en/bill/45-1/c-36
- Act to establish a legal framework for information technology, CQLR c C-1.1, ss. 44-45 (biometric filing requirements). https://www.legisquebec.gouv.qc.ca/en/document/cs/C-1.1
- Alberta Standing Committee on Resource Stewardship -- Final Report: Review of the Personal Information Protection Act (February 21, 2025). https://www.assembly.ab.ca/docs/default-source/committees/rs/final-pipa-report---web.pdf
- Government of Alberta -- Personal Information Protection Act engagement. https://www.alberta.ca/personal-information-protection-act-engagement
- PIPEDA Findings #2026-004 -- Commissioner-initiated complaints concerning X Corp. and X.AI LLC (June 11, 2026). https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-004/
- PIPEDA Findings #2025-003 -- Joint investigation of TikTok (September 23, 2025). https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2025/pipeda-2025-003/
- PIPEDA Findings #2026-001 -- Loblaw PC Optimum retention practices (March 5, 2026). https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-001/
Related Articles
- Canada Recording Laws: One-Party Consent Under the Criminal Code
- World Data Privacy Laws: Global Overview
- US Data Privacy Laws: State and Federal Guide
Last updated: 2026-09-09. Statutes cited reflect their in-force versions as of 2026-09-09.
Related Canadian Guides
Frequently Asked Questions
Does PIPEDA apply to all businesses in Canada?
PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity across Canada. However, in Alberta, British Columbia, and Quebec, provincial privacy laws deemed substantially similar to PIPEDA apply instead for intra-provincial commercial activity. PIPEDA still applies to federally regulated industries (banking, telecom, airlines) and to cross-border data transfers regardless of province. In all other provinces and territories, PIPEDA applies by default.
What happens if my organization suffers a data breach in Canada?
Under PIPEDA, you must assess whether the breach creates a real risk of significant harm (RROSH). If it does, you must report it to the Office of the Privacy Commissioner as soon as feasible, notify affected individuals directly, and notify any third-party organization that could reduce the risk of harm. You must also maintain records of all security incidents for at least 24 months, whether or not they triggered reporting. Knowingly failing to report or maintain records can result in fines up to CAD $100,000 per offence under PIPEDA s. 28. Quebec organizations face parallel obligations under Law 25.
How does Quebec Law 25 compare to the GDPR?
Quebec Law 25 is the closest North American equivalent to the GDPR. It requires explicit opt-in consent for cookies and tracking technologies, mandates a Privacy Impact Assessment for any project to acquire, develop or overhaul an information system involving personal information (s. 3.3) and before communicating personal information outside Quebec (s. 17), provides a private right of action with minimum $1,000 punitive damages, and imposes fines up to CAD $25 million or 4% of worldwide revenue for organizations. Key differences include Quebec-specific biometric filing requirements (prior disclosure to the CAI for identity verification, and disclosure at least 60 days before a biometric database is brought into service), individual penal caps of $100,000, and the absence of a formal DPO certification process comparable to GDPR Article 37.
Can Canadian organizations transfer personal data to other countries?
Yes. PIPEDA does not prohibit cross-border data transfers but requires organizations to ensure a comparable level of protection through contractual or other means. The transferring organization remains accountable for the data regardless of where it is processed. Quebec Law 25 is stricter, requiring a Privacy Impact Assessment before any transfer outside the province. The EU has recognized PIPEDA as providing adequate protection, allowing data to flow from the EU to PIPEDA-covered Canadian organizations without standard contractual clauses.
What is the current status of Canadian federal privacy reform?
Bill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act, died on the Order Paper in January 2025 when Parliament was prorogued. Its replacement, Bill C-36, was given first reading on June 15, 2026 and is at second reading in the House of Commons. It would enact the Protecting Privacy and Consumer Data Act, repeal Part 1 of PIPEDA, and allow administrative penalties of up to the greater of $10 million and 3% of gross global revenue. It is not law. Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent on March 26, 2026 and adds a data mobility framework to PIPEDA, but that Division is not yet in force. As of September 2026, PIPEDA still governs.
What did the OpenAI ChatGPT privacy investigation find?
In PIPEDA Findings #2026-002 (May 6, 2026), the OPC and three provincial regulators held that 'publicly available' information online is not exempt from privacy law obligations when collected for AI training. They accepted that developing and deploying ChatGPT is an appropriate purpose, but found that the manner in which OpenAI initially collected personal information from internet sources to train GPT-3.5 and 4, and the scale and nature of that collection, was overbroad and therefore inappropriate under PIPEDA s. 5(3). On consent, the OPC accepted that OpenAI may rely on implied consent where the privacy risk is significantly and meaningfully mitigated, and found the matter well-founded and conditionally resolved. The BC and Alberta commissioners found the consent issue well-founded and unresolved. The CAI found the appropriate-purposes, individual-rights and accountability issues conditionally resolved and the consent and retention issues unresolved.
Is there a right to be forgotten in Canada?
Canada does not have an explicit statutory right to erasure equivalent to GDPR Article 17. However, PIPEDA's retention limitation principle requires organizations to destroy personal information no longer needed for the purpose for which it was collected. In August 2025, the OPC's Google delist finding (PIPEDA Findings #2025-002) confirmed a limited right to delist under PIPEDA: in circumstances where a reasonable person would find it inappropriate for a search engine to continue returning links to personal information, an individual may request de-indexing. Quebec Law 25 provides an explicit right to de-indexing for digital content.
Does federal data portability apply to Canadian organizations now?
No. Bill C-15 (Budget 2025 Implementation Act, No. 1) received Royal Assent on March 26, 2026 and adds Division 1.2 to PIPEDA, under which an organization would have to disclose, on request, the personal information it collected from an individual to an organization that individual designates, provided both are subject to a data mobility framework set by regulation. Section 398 of that Act defers the Division to a day fixed by order of the Governor in Council. No order has been made and no framework regulations exist, so there is no federal portability obligation today. Quebec Law 25 portability has been in force since September 22, 2024.
What is the appropriate purposes test under PIPEDA?
Section 5(3) of PIPEDA requires that an organization may only collect, use, or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances. This test is separate from consent: even where consent is obtained, collection or use for an inappropriate purpose violates the Act. The OPC applied this test in the 2026 OpenAI investigation, accepting that developing and deploying ChatGPT was an appropriate purpose but finding that the manner in which OpenAI initially collected personal information from internet sources, and the scale and nature of that collection, was overbroad and therefore inappropriate.
How does Alberta's PIPA differ from PIPEDA?
Alberta's Personal Information Protection Act (SA 2003, c P-6.5) is substantially similar to PIPEDA and displaces it for intra-provincial private-sector activity. The OIPC-AB enforces Alberta PIPA rather than the federal OPC. Key practical differences include: the OIPC-AB can make binding orders under Alberta PIPA (the federal OPC cannot directly order compliance under PIPEDA), and Alberta PIPA's breach notification threshold and scope differ slightly from PIPEDA's. Alberta is currently conducting reform consultations following the Standing Committee's February 2025 report, which recommended adding administrative monetary penalty powers to the OIPC-AB.
Updates
Corrected the federal reform status: Bill C-36, the government's PIPEDA replacement, was tabled on June 15, 2026 and the page still said no bill existed; and Bill C-15's federal data-portability provisions, which the page said were in force, received Royal Assent on March 26, 2026 but await an order in council, so no federal portability right exists yet. Also corrected the Quebec biometric filing rule (it sits in the IT framework Act, and the 60-day lead time applies to creating a biometric database), the mandatory privacy impact assessment trigger, the scope of the Law 25 portability right, the basis of the CAI's facial-recognition order, and the OPC's OpenAI findings on consent and appropriate purposes.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Independently fact-checked against the cited primary sources
Major refresh: expanded from ~2,850 to ~5,500 words. Added Recent Enforcement Highlights section (OpenAI ChatGPT joint investigation May 2026, Google delist finding Aug 2025, CAI biometric order). Updated Bill C-15 status to passed (Royal Assent, March 26, 2026); the PIPEDA data mobility provisions are enacted but not in force pending an order in council. Expanded 45th Parliament reform outlook including Carney government priorities and potential 5% revenue penalty threshold. Expanded Alberta PIPA section with Standing Committee 12 recommendations (Feb 2025) and Spring 2026 public consultation. Added Appropriate Purposes Test section (PIPEDA s. 5(3)). Added Business Compliance Checklist section. Expanded FAQ from 5 to 10 pairs. Updated comparison table data portability row. Corrected individual penalties under Quebec Law 25 (admin cap $50,000 for individuals; penal cap $100,000 for individuals). Title and meta unchanged -- existing CTR metrics acceptable.
Reviewed and approved by an editor
Sources and References
- Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5(laws-lois.justice.gc.ca).gov
- PIPEDA Fair Information Principles -- Schedule 1(priv.gc.ca).gov
- OPC Guidelines for Obtaining Meaningful Consent(priv.gc.ca).gov
- Privacy Act, RSC 1985, c P-21 -- Full Text(laws-lois.justice.gc.ca).gov
- Canada's Privacy Act -- Department of Justice Overview(justice.gc.ca).gov
- Act respecting the protection of personal information in the private sector, CQLR c P-39.1 (Quebec Law 25)(legisquebec.gouv.qc.ca).gov
- Commission d'acces a l'information du Quebec (CAI)(cai.gouv.qc.ca).gov
- Osler -- Law 25 Enforcement Scheme for Protection of Personal Information in Quebec(osler.com)
- Osler -- Quebec Privacy Commissioner Sets High Bar for Biometric Data Processing(osler.com)
- Alberta Personal Information Protection Act (PIPA) -- Overview(alberta.ca).gov
- OPC Issue Sheets -- Review of Alberta PIPA (September 2024)(priv.gc.ca).gov
- British Columbia Personal Information Protection Act (PIPA) -- Full Text(bclaws.gov.bc.ca).gov
- Provincial Laws Deemed Substantially Similar to PIPEDA -- OPC(priv.gc.ca).gov
- Mandatory Breach Reporting Under PIPEDA -- OPC Guidance (SOR/2018-64)(priv.gc.ca).gov
- OPC Guidelines for Cross-Border Data Transfers(priv.gc.ca).gov
- European Commission Adequacy Decision Renewal -- Canada (January 15, 2024)(ec.europa.eu).gov
- Bill C-27 (44th Parliament, 1st Session) -- LEGISinfo(parl.ca).gov
- Fasken -- Prorogation's Digital Impact: Canada's Digital Bills Die on the Order Paper (January 2025)(fasken.com)
- IAPP -- What 2026 May Bring for Canada's Privacy Reform Efforts(iapp.org)
- Bill C-15 (45th Parliament, 1st Session) -- Budget 2025 Implementation Act, No. 1, SC 2026, c. 3 (Royal Assent, March 26, 2026)(parl.ca).gov
- OPC Statement on Bill C-15 to House of Commons Standing Committee (January 2026)(priv.gc.ca).gov
- OPC 2024-25 Annual Report -- Prioritizing Privacy in a Data-Driven World(priv.gc.ca).gov
- PIPEDA Findings #2026-002 -- Joint Investigation of OpenAI OpCo, LLC (May 2026)(priv.gc.ca).gov
- PIPEDA Findings #2025-002 -- Google Search Engine / Right to Delist (August 27, 2025)(priv.gc.ca).gov
- OPC Compliance Agreement -- World Anti-Doping Agency (2026)(priv.gc.ca).gov
- Osler -- Canada's 2026 Privacy Priorities: Data Sovereignty, Open Banking and AI(osler.com)