What Is PIPEDA (Personal Information Protection and Electronic Documents Act)?

Related problems: We sell to or employ people in Canada and don't know which privacy law applies; A Canadian customer asked where our vendors store their data; Not sure when a breach has to be reported to the Canadian privacy commissioner; Expanding into Quebec, Alberta or British Columbia

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada’s federal privacy law for the private sector. It sets out when organizations may collect, use and disclose personal information in the course of commercial activity, built around ten fair information principles such as accountability, consent and safeguards. It also covers employee information at federally regulated businesses such as banks, airlines and telecom carriers. This entry is an overview for buyers, not legal advice.

At a glance

  • PIPEDA applies to private-sector organizations handling personal information in commercial activity, and to employee data at federally regulated businesses.
  • Quebec, Alberta and British Columbia have substantially similar provincial laws, which generally govern activity within those provinces; PIPEDA still covers cross-border flows.
  • It is consent-based: organizations identify their purposes and generally need meaningful consent, express or implied depending on sensitivity.
  • Organizations stay accountable for data they hand to service providers, including providers outside Canada.
  • Breaches posing a real risk of significant harm must be reported to the Office of the Privacy Commissioner and to affected individuals, and every breach must be recorded.

What problem it solves

Canadian consumers and employees share personal information with businesses that store it in cloud platforms, CRMs, contact centers and payroll systems, often run by foreign providers. PIPEDA gives them a baseline: they should know why their information is collected, agree to its use, see what is held about them, and expect it to be protected. For organizations, it sets one national rulebook for commercial activity that crosses provincial lines.

For a mid-market buyer, PIPEDA usually appears when a Canadian customer asks about consent, data location or breach handling, or when a US company starts selling into Canada and needs to know whether its vendors’ contracts and security will stand up.

How it works

Ten principles. Organizations designate someone accountable, identify their purposes, obtain consent, limit collection, limit use, disclosure and retention, keep data accurate, protect it with safeguards suited to its sensitivity, be open about their practices, give individuals access, and let people challenge compliance.

Consent. Consent must be meaningful, meaning people should understand what they are agreeing to. The form required depends on the sensitivity of the information and people’s reasonable expectations.

Service providers. Transferring data to a provider for processing is treated as a use for the original purpose, not a new disclosure, but the organization remains accountable. Contracts should require comparable protection, and people should be told their data may be processed outside Canada.

Breaches. Breaches of security safeguards that create a real risk of significant harm must be reported to the Office of the Privacy Commissioner (OPC), with notice to affected individuals. Records of all breaches must be kept for at least two years.

Oversight. The OPC investigates complaints and can take some matters to the Federal Court. Reform proposals would add stronger enforcement, so watch for changes.

Which law applies

PIPEDA has no levels or tiers. Its closest structure is a split between federal and provincial laws, plus the roles of the organization and its service providers.

Situation Law that generally applies What is required Typical evidence
Commercial activity in most provinces and territories PIPEDA Ten principles, consent, safeguards, breach reporting Privacy policy, consent records, breach log
Commercial activity within Quebec, Alberta or British Columbia That province’s private-sector law Provincial rules, which can be stricter on some points Provincial compliance documentation
Data crossing provincial or national borders PIPEDA, often alongside a provincial law Both sets of rules where they overlap Transfer and vendor contract terms
Employee data at federally regulated businesses PIPEDA Same principles for employee information HR privacy notices and controls
Service provider processing for an organization The organization stays accountable under its applicable law Contractual protection comparable to the organization’s own Data processing terms, security reports

Provincial health-information laws can also apply to health data.

When it matters for buyers

  • When entering the Canadian market. Contracts and customers will expect consent, breach and data-location answers.
  • When choosing cloud, CCaaS or SaaS providers. You remain accountable for what they do with Canadian personal information.
  • When operating in Quebec. Its updated private-sector law adds requirements beyond PIPEDA, including for transfers outside the province.
  • When a breach happens. You need to decide quickly whether the real-risk threshold is met.

Our governance, risk and compliance overview covers advisors who map Canadian obligations to controls, and our public cloud overview covers regional hosting options.

Questions to ask vendors

  • Where is our data stored and processed, including backups, support access and subprocessors?
  • Can you host in a Canadian region, and does that cover every component of the service?
  • Which governments or courts could compel you to disclose our data?
  • Will your contract commit you to protection comparable to ours and to helping with access requests?
  • How quickly will you tell us about a breach, and what details will you give us to assess real risk of significant harm?
  • What independent security reports can you share, and are they scoped to this service?

How it differs from GDPR

Both PIPEDA and the General Data Protection Regulation (GDPR) are principle-based laws built on fair information practices. GDPR requires one of several lawful bases and has detailed rules on international transfers and much higher potential fines; PIPEDA centers on consent and accountability, lets data leave Canada under the organization’s continued responsibility, and has historically had more limited enforcement powers. Neither requires data residency as a general rule. Both define personal information more broadly than many US uses of personally identifiable information (PII), and both differ from the opt-out model of California’s CCPA. A data breach affecting several countries can trigger each regime’s notification rules at once, which is why a governance, risk and compliance (GRC) program tracks them together.

Frequently Asked Questions

Does PIPEDA require Canadian data to stay in Canada?
Generally no. PIPEDA lets organizations transfer personal information to service providers, including outside Canada, but they stay accountable for it, should protect it by contract and should be open with people that it may be processed elsewhere. Some provincial laws, public-sector rules and customer contracts set stricter location requirements, so check yours.
Does PIPEDA apply in Quebec, Alberta and British Columbia?
Those provinces have their own private-sector privacy laws that are considered substantially similar, so those laws generally govern commercial activity within the province. PIPEDA still applies to federally regulated businesses there and to personal information that crosses provincial or national borders. Many organizations end up subject to both; check with counsel. This is not legal advice.
When does a breach have to be reported under PIPEDA?
When it is reasonable to believe a breach of security safeguards creates a real risk of significant harm to an individual. Then the organization reports it to the Office of the Privacy Commissioner, notifies affected individuals as soon as feasible, and may need to tell other organizations that can reduce the harm. Every breach must be recorded, whether or not it is reported.
Is PIPEDA being replaced?
Possibly. Canada has tried several times to replace PIPEDA's privacy rules with a newer law, and reform bills have been introduced and lapsed. Until a replacement is passed and in force, PIPEDA applies. Check the current status with counsel or the Office of the Privacy Commissioner.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.