Canada's Meaningful Consent Guidelines Sort Themselves Into Must and Should. Here Is Which Is Which
Key Takeaways
- The guidelines are a joint document of the OPC and the Alberta and BC commissioners; Quebec's Commission d'accès à l'information is expressly not a signatory
- Footnote 4 sets the vocabulary: "must" indicates an obligation, "should" a recommended best practice, and the closing checklist sorts every item into those two lists
- Four elements are singled out for emphasis: what information is collected, with which parties it is shared, for what purposes, and the risk of harm and other consequences
- The checklist lists express consent for sensitive information, unexpected uses and meaningful residual risk of significant harm as a must, while Schedule 1 clause 4.3.6 of PIPEDA phrases express consent for sensitive information as something an organization "should generally" seek
- The OPC's position is that, in all but exceptional circumstances, a child under 13 cannot give meaningful consent; the Alberta and BC commissioners set no fixed age
The Statutory Hook: Principle 4.3 and Section 6.1
The consent guidelines interpret two layers of the Personal Information Protection and Electronic Documents Act, which the Justice Laws Website shows as current to 21 July 2026 and last amended on 4 March 2025.
The first is clause 4.3 of Schedule 1, Principle 3. It requires the knowledge and consent of the individual for collection, use or disclosure, except where inappropriate, and then spends eight subclauses on detail. Clause 4.3.2 requires purposes to be stated so that the individual can reasonably understand how the information will be used or disclosed. Clause 4.3.3 bars an organization from requiring consent, as a condition of supplying a product or service, beyond what is needed for explicitly specified and legitimate purposes. Clauses 4.3.4 and 4.3.5 make sensitivity and the individual's reasonable expectations relevant to the form of consent, and clause 4.3.5 adds that consent shall not be obtained through deception. Clause 4.3.8 lets an individual withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
The second is section 6.1, added by the Digital Privacy Act in 2015 (2015, c. 32, s. 5):
For the purposes of clause 4.3 of Schedule 1, the consent of an individual is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.
PIPEDA, section 6.1
Section 6.1 measures understanding against the audience an organization targets, not against a hypothetical average reader. Most of the guidelines are an account of what that test implies.
Who Issued the Guidelines and When
The Guidelines for obtaining meaningful consent were issued on 24 May 2018 and the page records a last modification on 11 August 2025. They are a joint product of the Office of the Privacy Commissioner of Canada and the Information and Privacy Commissioners of Alberta and British Columbia, and state that they reflect the principles underlying PIPEDA and its substantially similar provincial counterparts. Footnote 2 records that Quebec's Commission d'accès à l'information is not a signatory.
The joint authorship has a limit the document itself marks. Footnote 8 notes that the section 6.1 language on understanding consequences is not currently in the Personal Information Protection Acts of Alberta or British Columbia, and the overview says that while the statutes share underlying principles, some differences exist.
Must and Should: How the Guidelines Label Themselves
The guidelines define their own vocabulary in footnote 4: the word must indicates an obligation, and should indicates a recommended best practice. They then close with a checklist that separates obligations arising from legal requirements from best practices, under the headings "Must do" and "Should do". That labelling is the regulators' reading of what the law requires; the guidelines are not themselves a regulation, and this post reports the labels as the document applies them.
| Checklist: Must do | Checklist: Should do |
|---|---|
| Make privacy information readily available in complete form, emphasising the four key elements | Let individuals control how much detail they receive, and when |
| Provide information in manageable and easily accessible ways | Design or adopt just-in-time, context-specific consent processes suited to the interface |
| Give a clear, easily accessible choice for any collection, use or disclosure not necessary to the product or service | Periodically remind individuals of their consent choices |
| Consider the consumer's perspective so processes are user-friendly and understandable | Periodically audit privacy communications against actual practice |
| Obtain consent before significant changes, such as new purposes or new third parties | Stand ready to demonstrate compliance, including that the process is understandable to users |
| Limit collection, use and disclosure to purposes a reasonable person would consider appropriate | Consider user consultation, pilot testing, UI/UX designers, privacy experts or regulators, and established standards |
| Allow withdrawal of consent, subject to legal or contractual restrictions | |
| Obtain express consent in the three situations described below | |
| Obtain consent from a parent or guardian for anyone unable to consent meaningfully |
One item is worth reading beside the statute. PIPEDA section 5(2) provides that "should" in Schedule 1 indicates a recommendation and does not impose an obligation, and clause 4.3.6 states that an organization "should generally seek express consent when the information is likely to be considered sensitive". The guidelines' checklist places express consent for sensitive information on the must side, and their body text ties that position to the Supreme Court of Canada's 2016 decision in Royal Bank of Canada v. Trang on sensitivity and reasonable expectations. The two documents use different verbs for the same subject, and this post does not resolve which governs a given case.
The Seven Guiding Principles
- Emphasize key elements. Information must be complete and available, but four elements warrant emphasis up front: what personal information is collected; with which parties it is shared; for what purposes; and the risk of harm and other consequences
- Allow individuals to control the level of detail they get and when. Layered presentation is offered as one method, and information should remain available as individuals continue to engage
- Provide clear options to say yes or no. Anything beyond what is necessary to provide the product or service requires a choice; a condition of service is valid only if integral to providing the product or service
- Be innovative and creative. The guidelines name just-in-time notices, interactive tools and customized mobile interfaces
- Consider the consumer's perspective. Consent processes must be generally understandable to the organization's target audience
- Make consent a dynamic and ongoing process. Significant changes, including new purposes or new third-party disclosures, require notice and consent before they take effect
- Be accountable. The guidelines state that pointing to a line buried in a privacy policy will not suffice to demonstrate valid consent
The first principle carries the most specific language. Purposes are to be described in meaningful terms, and the guidelines give "service improvement" as an example of the vagueness to avoid. On risk, the OPC's position is that a meaningful residual risk of significant harm, meaning a risk remaining after mitigation that falls below the balance of probabilities but is more than a minimal or mere possibility, must be notified. Significant harm is defined by reference to PIPEDA's breach provision: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. Where the risk of significant harm is likely rather than merely meaningful, the guidelines treat the purpose as generally inappropriate under subsection 5(3), and so not something consent can cure.
Express Versus Implied Consent
The guidelines state that consent should generally be express and can be implied only in strictly defined circumstances. They list three situations in which organizations must generally obtain express consent:
- The information is sensitive, where there is no bright line: health and financial information generally is, as are ethnic and racial origins, political opinions, genetic data, uniquely identifying biometric data, sex life or sexual orientation, and religious or philosophical beliefs, and otherwise innocuous information can become sensitive in combination
- The collection, use or disclosure is outside the individual's reasonable expectations, with examples including certain third-party sharing, downloading photos or contact lists, and location tracking
- The collection, use or disclosure creates a meaningful residual risk of significant harm
Schedule 1 itself illustrates the older, broader range of acceptable forms. Clause 4.3.7 gives four examples of ways consent can be given, including a check-off box for asking that names and addresses not be passed to other organizations, with anyone who leaves it unticked assumed to consent to the transfer, oral consent by telephone, and consent at the time a product or service is used.
Inappropriate Purposes: the No-Go Zones
The consent guidelines close by reminding readers that consent is not a free pass, and point to a companion document published the same day, the OPC's Guidance on inappropriate data practices. Unlike the consent guidelines, that document is the federal office's alone. It interprets subsection 5(3), which limits collection, use and disclosure to purposes a reasonable person would consider appropriate in the circumstances, and lists the factors from Turner v. Telus Communications: the sensitivity of the information, whether the purpose represents a legitimate need, whether the practice would be effective, whether less invasive means exist at comparable cost and benefit, and whether the loss of privacy is proportional to the benefit.
It then identifies six purposes the OPC generally considers offside PIPEDA from a reasonable person's perspective:
- Collection, use or disclosure that is otherwise unlawful, with examples from credit reporting law and the Genetic Non-Discrimination Act
- Profiling or categorization that leads to unfair, unethical or discriminatory treatment contrary to human rights law
- Collection, use or disclosure for purposes known or likely to cause significant harm to the individual
- Publishing personal information with the intended purpose of charging individuals for its removal
- Requiring passwords to social media accounts for the purpose of employee screening
- Surveillance through the audio or video functionality of the individual's own device
The document says the list may evolve, and footnote 10 leaves room for exceptional cases in which contextual factors make a listed use appropriate. Its page records no modification since 24 May 2018.
Consent and Children
This is the section where the three signatories visibly part. The OPC takes the position that, in all but exceptional circumstances, anyone under the age of 13 cannot give meaningful consent, so consent must come from a parent or guardian. The Alberta and British Columbia commissioners, along with Quebec's Commission, set no specific age threshold and instead ask whether the individual understands the nature and consequences of exercising the right in question. For minors who can consent, the guidelines state that consent is meaningful only if the organization has reasonably taken their level of maturity into account in designing the process.
Alberta's statute writes a version of the provincial approach into law. Section 61 of the Alberta Personal Information Protection Act allows a person under 18 to exercise their own rights and powers under the Act if they understand the nature of the right or power and the consequences of exercising it, and otherwise lets a guardian do so.
Withdrawal, and What Consent Does Not Waive
The final section adds two points. Withdrawal of consent should stop further collection and use, and may mean deletion, with retained "do not contact" lists and legally required retention given as limits. And consent does not waive an organization's other obligations, such as accountability, collection limitation and safeguards: in the guidelines' words, an organization handling information contrary to legal requirements would still be in contravention even if the individual had consented.
Frequently Asked Questions
Are the OPC's meaningful consent guidelines legally binding?
What are the four key elements the consent guidelines say must be emphasised?
When do the guidelines say express consent is required under PIPEDA?
What age does the OPC treat as too young to consent?
What are the OPC's no-go zones?
Sources
Everything above is reported from these documents. Follow them to verify.
- Office of the Privacy Commissioner of Canada, OIPC Alberta and OIPC British Columbia, Guidelines for obtaining meaningful consent (August 11, 2025) agency guidance
- Office of the Privacy Commissioner of Canada, Guidance on inappropriate data practices: Interpretation and application of subsection 5(3) (May 24, 2018) agency guidance
- Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, consolidated text current to 2026-07-21 (Justice Laws Website) (July 21, 2026) statute
- Personal Information Protection Act, SA 2003, c P-6.5, office consolidation current as of September 1, 2025 (Alberta King's Printer) (September 1, 2025) statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.