Canada (PIPEDA)

Canada Has a Federal Privacy Law With No Fines, and a Province With Very Large Ones

Key Takeaways

  • PIPEDA does not apply to organizations operating entirely within Alberta, British Columbia or Quebec unless the information crosses a provincial or national border, because those provinces have laws declared substantially similar
  • PIPEDA's substantive obligations sit in Schedule 1, and section 5(2) provides that the word "should" in that Schedule "indicates a recommendation and does not impose an obligation"
  • Breach reporting under section 10.1 is triggered by a real risk of significant harm and is owed "as soon as feasible", with no fixed number of days; section 10.3 requires a record of every breach regardless of risk
  • The federal Privacy Commissioner issues findings rather than fines: PIPEDA's only monetary sanction is a section 28 offence capped at $100,000 on indictment
  • Quebec's Law 25 provides administrative penalties up to $10,000,000 or 2% of worldwide turnover, penal fines up to $25,000,000 or 4%, and punitive damages of not less than $1,000

Which Statute Applies Is a Question About Geography

Most national privacy regimes ask what a company does. Canada's first asks where it is, and whether its data stays there.

The Personal Information Protection and Electronic Documents Act is federal, but section 26(2)(b) lets the Governor in Council exempt organizations from it where a province has enacted legislation "that is substantially similar to this Part" — and where the processing occurs within that province. The result is a map rather than a rule. The Office of the Privacy Commissioner's summary of privacy laws in Canada sets it out:

  • PIPEDA generally applies to private-sector organizations conducting business in Manitoba, New Brunswick, Newfoundland and Labrador, the Northwest Territories, Nova Scotia, Nunavut, Ontario, Prince Edward Island, Saskatchewan and Yukon
  • It does not apply to organizations operating entirely within Alberta, British Columbia or Quebec, which have general private-sector laws deemed substantially similar — unless the personal information crosses a provincial or national border
  • Organizations in the Northwest Territories, Yukon and Nunavut are treated as federally regulated and are therefore covered by PIPEDA
  • Federally regulated businesses — the OPC names banks, airlines and telecommunications companies — are always subject to PIPEDA, and must apply it to their employees' personal information as well as their customers'
  • Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia have health privacy laws declared substantially similar with respect to health information

The border-crossing clause is the operative one for most companies outside Canada. The OPC states that all businesses operating in Canada and handling personal information that crosses provincial or national borders are subject to PIPEDA regardless of where they are based. A company sending Canadian customer data to a US server is, by that description, in PIPEDA territory whichever province the customer sits in — and potentially in provincial territory as well. The OPC page carries a date modified of 31 January 2018, so it maps the allocation of jurisdiction rather than the current content of each province's statute.

That overlap is not theoretical. The 2025 joint investigation discussed below was conducted by four regulators simultaneously, each applying its own statute to the same conduct.

PIPEDA's Obligations Sit in a Schedule, and Some Are Recommendations

PIPEDA is unusual among modern privacy statutes in that its substantive requirements are not in the body of the Act. Section 5(1) of the Act provides that every organization shall comply with the obligations set out in Schedule 1, and Schedule 1 is a code — ten principles beginning at clause 4.1 with Accountability, which requires an organization to designate an individual or individuals accountable for compliance.

The consequence of legislating by incorporated code is a drafting register the statute has to correct for. Section 5(2) does that explicitly: "The word should, when used in Schedule 1, indicates a recommendation and does not impose an obligation." A reader working through Schedule 1 is therefore reading two kinds of sentence, and the difference between them is the difference between a duty and advice.

Two provisions in the body of the Act do heavier work than any single principle. Section 5(3) states that an organization "may collect, use or disclose personal information only for purposes that a reasonable person would consider are appropriate in the circumstances" — an objective ceiling that consent cannot raise. Section 6.1 then limits consent itself: consent is valid "only if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences" of the processing. Section 6 adds that designating an accountable individual under clause 4.1 does not relieve the organization of its own obligations.

Section 3 frames the whole thing as a balance rather than a right, describing the purpose as rules that recognize "the right of privacy of individuals" alongside "the need of organizations to collect, use or disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances".

Breach Reporting Has a Threshold but No Deadline

Section 10.1(1) requires an organization to report to the Commissioner any breach of security safeguards involving personal information under its control "if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual." Section 10.1(3) requires notification to the affected individual on the same trigger, unless otherwise prohibited by law.

The timing language is the part that differs sharply from the 72-hour clock familiar from European law. Subsections 10.1(2), 10.1(6) and 10.2(2) each require the report or notification to be made "as soon as feasible after the organization determines that the breach has occurred." No number of hours or days appears. The clock is also anchored to determination rather than to awareness.

Section 10.1(8) lists the factors relevant to whether a real risk of significant harm exists, and section 10.2(1) adds an onward duty: an organization notifying an individual must also notify any other organization or government institution that it believes may be able to reduce or mitigate the risk of harm.

Section 10.3(1) is separate and easy to miss, because it has no threshold at all. An organization "shall, in accordance with any prescribed requirements, keep and maintain a record of every breach of security safeguards involving personal information under its control" — every breach, whether or not it creates a real risk of significant harm, and whether or not it was reported.

The Federal Commissioner Cannot Fine Anyone

This is the single most consequential structural fact about PIPEDA, and it has no counterpart in the EU, UK, Brazilian or Chinese regimes.

Under section 11 an individual may file a written complaint with the Commissioner. The Commissioner investigates and issues a report. What the Commissioner cannot do is impose a monetary penalty for the contravention. Section 14 instead gives the complainant — not the regulator — the right to apply to the Federal Court for a hearing after receiving the Commissioner's report, in respect of the specified Schedule 1 clauses and statutory provisions listed there. Section 17(1) requires such an application to be heard "without delay and in a summary way" unless the Court considers that inappropriate.

PIPEDA's only monetary sanction is criminal and narrow. Section 28 makes it an offence to knowingly contravene subsection 8(8), section 10.1, or subsection 10.3(1) or 27.1(1), or to obstruct the Commissioner in an investigation or audit. The penalty is a fine not exceeding $10,000 on summary conviction, or not exceeding $100,000 on indictment. The breach-reporting and breach-recording duties are inside that list; the substance of Schedule 1 is not.

What enforcement looks like in practice is therefore a published finding. In PIPEDA Findings #2025-003, the OPC together with the Commission d'accès à l'information du Québec and the information and privacy commissioners of British Columbia and Alberta investigated TikTok Pte. Ltd. The offices found that TikTok's measures to keep children off the platform were inadequate, recording that TikTok removes approximately 500,000 underage users each year and that it was collecting and inferring information about them for ad targeting and content recommendation before removal. They found deficiencies in the consent obtained from youth users, and found that TikTok's use of facial and voice analytics to infer age and gender was not adequately explained — while noting that the implementation was not designed to support facial recognition or user identification.

The disposition is the point. TikTok "generally disagreed with the findings" but agreed to work with the offices, and the report concludes: "we find this matter to be well-founded and conditionally resolved." A finding, a set of commitments, and a conditional resolution — with no penalty attached. The report also records the jurisdictional overlap in a single line of detail: TikTok's terms prohibit users under 13, "14 in Quebec".

Quebec Is Where the Money Is

The Act respecting the protection of personal information in the private sector, as amended by the 2021 statute generally called Law 25, carries penalties on a different order of magnitude from anything federal — and in three separate tracks.

TrackProvisionMaximum
Monetary administrative penaltys. 90.12$50,000 for a natural person; otherwise $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is greater
Penal offences. 91$5,000 to $100,000 for a natural person; otherwise $15,000 to $25,000,000 or 4% of worldwide turnover, whichever is greater
Punitive damagess. 93.1Not less than $1,000 where an unlawful infringement causing injury is intentional or results from gross fault

Section 93.1 deserves separate attention because it is a statutory private right of action with a damages floor. Where the unlawful infringement of a right conferred by the Act, or by articles 35 to 40 of the Civil Code, causes an injury and the infringement is intentional or results from a gross fault, "the court shall award punitive damages of not less than $1,000." That is a mandatory minimum, expressed as shall, and it sits on top of whatever compensatory damages the injury supports.

The Commission d'accès à l'information also has an order power that operates before any of this. Section 81.4 permits it, when a confidentiality incident is brought to its attention, to order any person — after giving them an opportunity to submit observations — to take any measure to protect the rights of the persons concerned, including ordering that the information be returned or destroyed.

Quebec's Substantive Duties Have No Federal Equivalent

The penalties get the attention, but the obligations they attach to are the larger divergence. Several have no counterpart in PIPEDA at all:

  • Section 3.1. The person exercising the highest authority within the enterprise is by default the person in charge of the protection of personal information, and may delegate the function only in writing. That person's title and contact information must be published on the enterprise's website
  • Section 3.2. Governance policies and practices are mandatory, must be approved by the person in charge, and detailed information about them must be published in simple and clear language
  • Section 3.3. A privacy impact assessment is required for any project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information, and the project must allow information collected from a person to be communicated to them in a structured, commonly used technological format
  • Section 8.1. Collecting personal information using technology with functions allowing a person to be identified, located or profiled requires informing them first of the use of the technology and of the means to deactivate those functions
  • Section 9.1. A technological product or service offered to the public that has privacy settings must have those settings at the highest level of confidentiality by default, without any intervention by the person concerned
  • Section 12.1. A decision based exclusively on automated processing requires informing the person no later than when they are told of the decision
  • Section 17. A privacy impact assessment is required before communicating personal information outside Quebec, taking into account the sensitivity of the information among other factors
  • Section 28.1. A person may require an enterprise to cease disseminating information about them, or to de-index a hyperlink attached to their name, where the dissemination contravenes the law or a court order

Breach terminology also differs. Quebec uses "confidentiality incident", defined in section 3.6 to include access to personal information not authorized by law. Section 3.5 imposes a duty to take reasonable measures to reduce the risk of injury and prevent new incidents of the same nature. Section 3.7 requires the risk assessment to consider the sensitivity of the information, the anticipated consequences of its use and the likelihood of injurious use, and requires consultation with the person in charge. Section 3.8 requires a register of confidentiality incidents — the Quebec analogue of PIPEDA's section 10.3 record.

Access and portability sit in section 27. An enterprise must confirm the existence of personal information, communicate it, and allow a copy to be obtained. Computerized information collected from the applicant — but expressly "not created or inferred using personal information concerning him" — must, on request and unless doing so raises serious practical difficulties, be communicated in a structured, commonly used technological format, and may be sent to any person or body authorized by law to collect it.

Federal Reform: One Amendment Enacted, One Bill Pending

Federal reform has been attempted repeatedly without a comprehensive statute reaching the books, and the current position is best described as two separate things happening at once.

The first is already law but not yet operative. The consolidated PIPEDA text on the Justice Laws Website carries an "AMENDMENTS NOT IN FORCE" block recording that 2026, c. 3, s. 389 adds a new Division 1.2, "Mobility of Personal Information", after section 10.3. New section 10.4 would require an organization, on an individual's request, to disclose personal information it collected from that individual to an organization the individual designates — but only where both organizations are subject to a data mobility framework, and subject to regulations. New section 10.5 gives the Governor in Council power to make those regulations after consulting the OPC, covering safeguards, interoperability parameters, which organizations are within a framework, and exceptions including for proprietary or confidential commercial information.

Privacy Commissioner Philippe Dufresne addressed those provisions in a statement to the House of Commons Standing Committee on Industry and Technology on 26 January 2026, on Part 5, Division 23 of Bill C-15, the Budget 2025 Implementation Act, No. 1. He supported introducing a right to data mobility, and — given how much is left to regulation — said it would be important for his office to be consulted as those regulations are developed.

The second is a comprehensive bill that has not passed. Bill C-36, "An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts", was introduced and given first reading in the House of Commons on 15 June 2026 and is recorded on LEGISinfo as at second reading, with no committee consideration, report stage, third reading or Senate stage reached.

What that bill would do to the enforcement gap described above is not something this guide takes a position on. A bill at second reading is not law, its text can change in committee, and Canadian privacy reform bills have died on the order paper before.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

Does PIPEDA apply to a company operating only in Quebec?
Generally not. The OPC states that PIPEDA does not apply to organizations that operate entirely within Alberta, British Columbia or Quebec, because those provinces have general private-sector laws deemed substantially similar — unless the personal information crosses a provincial or national border. Federally regulated businesses such as banks, airlines and telecommunications companies are subject to PIPEDA wherever they operate.
How many days does PIPEDA give to report a breach?
It gives no number. Subsections 10.1(2) and 10.1(6) require the report to the Commissioner and the notification to the individual to be made "as soon as feasible after the organization determines that the breach has occurred." The reporting duty is triggered only where it is reasonable to believe the breach creates a real risk of significant harm, but section 10.3(1) separately requires a record of every breach regardless of risk.
Can the Privacy Commissioner of Canada issue a fine?
Not for a contravention of Schedule 1. The Commissioner investigates complaints under section 11 and issues a report; under section 14 it is the complainant who may then apply to the Federal Court. PIPEDA's only monetary sanction is the section 28 offence — knowingly contravening the breach-reporting or breach-recording duties, or obstructing the Commissioner — capped at $10,000 on summary conviction and $100,000 on indictment.
What does "well-founded and conditionally resolved" mean?
It is the disposition the OPC and its provincial counterparts reached in PIPEDA Findings #2025-003 concerning TikTok. The offices found the complaint substantiated, TikTok generally disagreed with the findings but agreed to implement measures the offices accepted, and the matter was resolved on condition that those commitments are carried out. No penalty accompanied it.
How large can a Quebec Law 25 penalty be?
Section 90.12 caps a monetary administrative penalty at $50,000 for a natural person, and otherwise at $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is greater. Section 91 sets penal fines of $5,000 to $100,000 for a natural person, and otherwise $15,000 to $25,000,000 or 4% of worldwide turnover, whichever is greater.
Is there a private right of action for privacy violations in Canada?
In Quebec, section 93.1 of the private sector Act provides that where an unlawful infringement of a right conferred by that Act or by articles 35 to 40 of the Civil Code causes injury, and the infringement is intentional or results from gross fault, the court shall award punitive damages of not less than $1,000. Federally, section 14 of PIPEDA lets a complainant apply to the Federal Court after the Commissioner reports, in respect of the provisions listed in that section.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.