Canada

Substantial

PIPEDA + Provincial Laws (Bill C-27 pending)

Authority: Office of the Privacy Commissioner (OPC) | Enforcement: Active | Enacted: January 2001

Overview

Canada's federal private sector privacy law is PIPEDA, which has EU adequacy status. Bill C-27 (Consumer Privacy Protection Act) seeks to modernise the framework with GDPR-like provisions. Quebec's Law 25 (effective 2023-2024) is the most comprehensive provincial law. Alberta and BC have substantially similar provincial legislation.

14-Topic Coverage

Data Protection Authority

Fully Addressed

OPC Canada investigates complaints, conducts audits, and publishes findings. Currently lacks order-making power (Bill C-27 would add this). Provincial commissioners in Quebec, Alberta, BC.

PIPEDA Part 1, Privacy Act

Data Subject Rights

Fully Addressed

Right to access personal information and challenge accuracy. Right to know about organisational practices. Complaint to OPC.

PIPEDA Principles 8-9

Cross-Border Transfer

Partially Addressed

Transfers permitted with comparable protection by contract. No adequacy mechanism. OPC guidance requires accountability measures.

PIPEDA Principle 1, OPC Guidelines

Breach Notification

Fully Addressed

Mandatory breach reporting to OPC and notification to individuals for breaches posing real risk of significant harm (since 2018 PIPEDA amendments).

PIPEDA Division 1.1

DPO Requirements

Partially Addressed

Must designate individual(s) accountable for compliance (Accountability Principle). Not formally called DPO but serves similar function.

PIPEDA Principle 1

Children's Data

Partially Addressed

OPC guidance considers children generally incapable of providing meaningful consent. No specific age threshold in PIPEDA. Quebec Law 25 sets age at 14.

OPC Guidelines on Youth Consent

Penalties & Enforcement

Partially Addressed

PIPEDA currently has limited enforcement (no fines, only compliance agreements and Federal Court applications). Bill C-27 proposes penalties up to 5% of global revenue.

PIPEDA Part 1, Bill C-27

Sector-Specific Rules

Fully Addressed

PHIPA (health in Ontario), FIPPA (public sector), bank and telecom regulations. CASL governs electronic marketing.

CASL, provincial health privacy laws

AI & Automated Decisions

Partially Addressed

Bill C-27 includes Artificial Intelligence and Data Act (AIDA). Directive on Automated Decision-Making applies to federal government. No current private sector AI law.

Bill C-27 AIDA, Treasury Board Directive

Data Localisation

Not Addressed

No general data localisation requirement. Provincial government data may have residency requirements.

Provincial policies

Significant Data Fiduciary

Not Addressed

No direct equivalent. PIPEDA applies to all commercial activities regardless of organisation size.

PIPEDA general application

Government Data

Fully Addressed

Federal Privacy Act governs government institutions. Access to Information Act provides transparency. PIPEDA covers private sector only.

Privacy Act (Canada), Access to Information Act

Key Statistics

Maximum Penalty
PIPEDA: limited; Bill C-27: up to 5% of global revenue
Authority
OPC Canada

Coverage Summary

Fully Addressed6/14
Partially Addressed6/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Canada's regulations.

Book a Consultation