Canada
SubstantialPIPEDA + Provincial Laws (Bill C-27 pending)
Authority: Office of the Privacy Commissioner (OPC) | Enforcement: Active | Enacted: January 2001
Overview
Canada's federal private sector privacy law is PIPEDA, which has EU adequacy status. Bill C-27 (Consumer Privacy Protection Act) seeks to modernise the framework with GDPR-like provisions. Quebec's Law 25 (effective 2023-2024) is the most comprehensive provincial law. Alberta and BC have substantially similar provincial legislation.
14-Topic Coverage
Data Protection Authority
Fully AddressedOPC Canada investigates complaints, conducts audits, and publishes findings. Currently lacks order-making power (Bill C-27 would add this). Provincial commissioners in Quebec, Alberta, BC.
Consent Requirements
Fully AddressedMeaningful consent is central. Knowledge and consent required with limited exceptions. Implied consent available for less sensitive processing.
Data Subject Rights
Fully AddressedRight to access personal information and challenge accuracy. Right to know about organisational practices. Complaint to OPC.
Cross-Border Transfer
Partially AddressedTransfers permitted with comparable protection by contract. No adequacy mechanism. OPC guidance requires accountability measures.
Breach Notification
Fully AddressedMandatory breach reporting to OPC and notification to individuals for breaches posing real risk of significant harm (since 2018 PIPEDA amendments).
DPO Requirements
Partially AddressedMust designate individual(s) accountable for compliance (Accountability Principle). Not formally called DPO but serves similar function.
Children's Data
Partially AddressedOPC guidance considers children generally incapable of providing meaningful consent. No specific age threshold in PIPEDA. Quebec Law 25 sets age at 14.
Penalties & Enforcement
Partially AddressedPIPEDA currently has limited enforcement (no fines, only compliance agreements and Federal Court applications). Bill C-27 proposes penalties up to 5% of global revenue.
Sector-Specific Rules
Fully AddressedPHIPA (health in Ontario), FIPPA (public sector), bank and telecom regulations. CASL governs electronic marketing.
Cookie/Tracking
Partially AddressedCASL requires consent for installing programs. PIPEDA consent requirements apply to cookie tracking. No specific cookie regulation.
AI & Automated Decisions
Partially AddressedBill C-27 includes Artificial Intelligence and Data Act (AIDA). Directive on Automated Decision-Making applies to federal government. No current private sector AI law.
Data Localisation
Not AddressedNo general data localisation requirement. Provincial government data may have residency requirements.
Significant Data Fiduciary
Not AddressedNo direct equivalent. PIPEDA applies to all commercial activities regardless of organisation size.
Government Data
Fully AddressedFederal Privacy Act governs government institutions. Access to Information Act provides transparency. PIPEDA covers private sector only.
Key Statistics
- Maximum Penalty
- PIPEDA: limited; Bill C-27: up to 5% of global revenue
- Authority
- OPC Canada
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Canada's regulations.
Book a Consultation