Canada (PIPEDA)

Canada's Meaningful Consent Guidelines Sort Themselves Into Must and Should. Here Is Which Is Which

Key Takeaways

  • The guidelines are a joint document of the OPC and the Alberta and BC commissioners; Quebec's Commission d'accès à l'information is expressly not a signatory
  • Footnote 4 sets the vocabulary: "must" indicates an obligation, "should" a recommended best practice, and the closing checklist sorts every item into those two lists
  • Four elements are singled out for emphasis: what information is collected, with which parties it is shared, for what purposes, and the risk of harm and other consequences
  • The checklist lists express consent for sensitive information, unexpected uses and meaningful residual risk of significant harm as a must, while Schedule 1 clause 4.3.6 of PIPEDA phrases express consent for sensitive information as something an organization "should generally" seek
  • The OPC's position is that, in all but exceptional circumstances, a child under 13 cannot give meaningful consent; the Alberta and BC commissioners set no fixed age

The Statutory Hook: Principle 4.3 and Section 6.1

The consent guidelines interpret two layers of the Personal Information Protection and Electronic Documents Act, which the Justice Laws Website shows as current to 21 July 2026 and last amended on 4 March 2025.

The first is clause 4.3 of Schedule 1, Principle 3. It requires the knowledge and consent of the individual for collection, use or disclosure, except where inappropriate, and then spends eight subclauses on detail. Clause 4.3.2 requires purposes to be stated so that the individual can reasonably understand how the information will be used or disclosed. Clause 4.3.3 bars an organization from requiring consent, as a condition of supplying a product or service, beyond what is needed for explicitly specified and legitimate purposes. Clauses 4.3.4 and 4.3.5 make sensitivity and the individual's reasonable expectations relevant to the form of consent, and clause 4.3.5 adds that consent shall not be obtained through deception. Clause 4.3.8 lets an individual withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.

The second is section 6.1, added by the Digital Privacy Act in 2015 (2015, c. 32, s. 5):

For the purposes of clause 4.3 of Schedule 1, the consent of an individual is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.

PIPEDA, section 6.1

Section 6.1 measures understanding against the audience an organization targets, not against a hypothetical average reader. Most of the guidelines are an account of what that test implies.

Who Issued the Guidelines and When

The Guidelines for obtaining meaningful consent were issued on 24 May 2018 and the page records a last modification on 11 August 2025. They are a joint product of the Office of the Privacy Commissioner of Canada and the Information and Privacy Commissioners of Alberta and British Columbia, and state that they reflect the principles underlying PIPEDA and its substantially similar provincial counterparts. Footnote 2 records that Quebec's Commission d'accès à l'information is not a signatory.

The joint authorship has a limit the document itself marks. Footnote 8 notes that the section 6.1 language on understanding consequences is not currently in the Personal Information Protection Acts of Alberta or British Columbia, and the overview says that while the statutes share underlying principles, some differences exist.

Must and Should: How the Guidelines Label Themselves

The guidelines define their own vocabulary in footnote 4: the word must indicates an obligation, and should indicates a recommended best practice. They then close with a checklist that separates obligations arising from legal requirements from best practices, under the headings "Must do" and "Should do". That labelling is the regulators' reading of what the law requires; the guidelines are not themselves a regulation, and this post reports the labels as the document applies them.

Checklist: Must doChecklist: Should do
Make privacy information readily available in complete form, emphasising the four key elementsLet individuals control how much detail they receive, and when
Provide information in manageable and easily accessible waysDesign or adopt just-in-time, context-specific consent processes suited to the interface
Give a clear, easily accessible choice for any collection, use or disclosure not necessary to the product or servicePeriodically remind individuals of their consent choices
Consider the consumer's perspective so processes are user-friendly and understandablePeriodically audit privacy communications against actual practice
Obtain consent before significant changes, such as new purposes or new third partiesStand ready to demonstrate compliance, including that the process is understandable to users
Limit collection, use and disclosure to purposes a reasonable person would consider appropriateConsider user consultation, pilot testing, UI/UX designers, privacy experts or regulators, and established standards
Allow withdrawal of consent, subject to legal or contractual restrictions
Obtain express consent in the three situations described below
Obtain consent from a parent or guardian for anyone unable to consent meaningfully

One item is worth reading beside the statute. PIPEDA section 5(2) provides that "should" in Schedule 1 indicates a recommendation and does not impose an obligation, and clause 4.3.6 states that an organization "should generally seek express consent when the information is likely to be considered sensitive". The guidelines' checklist places express consent for sensitive information on the must side, and their body text ties that position to the Supreme Court of Canada's 2016 decision in Royal Bank of Canada v. Trang on sensitivity and reasonable expectations. The two documents use different verbs for the same subject, and this post does not resolve which governs a given case.

The Seven Guiding Principles

  1. Emphasize key elements. Information must be complete and available, but four elements warrant emphasis up front: what personal information is collected; with which parties it is shared; for what purposes; and the risk of harm and other consequences
  2. Allow individuals to control the level of detail they get and when. Layered presentation is offered as one method, and information should remain available as individuals continue to engage
  3. Provide clear options to say yes or no. Anything beyond what is necessary to provide the product or service requires a choice; a condition of service is valid only if integral to providing the product or service
  4. Be innovative and creative. The guidelines name just-in-time notices, interactive tools and customized mobile interfaces
  5. Consider the consumer's perspective. Consent processes must be generally understandable to the organization's target audience
  6. Make consent a dynamic and ongoing process. Significant changes, including new purposes or new third-party disclosures, require notice and consent before they take effect
  7. Be accountable. The guidelines state that pointing to a line buried in a privacy policy will not suffice to demonstrate valid consent

The first principle carries the most specific language. Purposes are to be described in meaningful terms, and the guidelines give "service improvement" as an example of the vagueness to avoid. On risk, the OPC's position is that a meaningful residual risk of significant harm, meaning a risk remaining after mitigation that falls below the balance of probabilities but is more than a minimal or mere possibility, must be notified. Significant harm is defined by reference to PIPEDA's breach provision: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. Where the risk of significant harm is likely rather than merely meaningful, the guidelines treat the purpose as generally inappropriate under subsection 5(3), and so not something consent can cure.

Express Versus Implied Consent

The guidelines state that consent should generally be express and can be implied only in strictly defined circumstances. They list three situations in which organizations must generally obtain express consent:

  • The information is sensitive, where there is no bright line: health and financial information generally is, as are ethnic and racial origins, political opinions, genetic data, uniquely identifying biometric data, sex life or sexual orientation, and religious or philosophical beliefs, and otherwise innocuous information can become sensitive in combination
  • The collection, use or disclosure is outside the individual's reasonable expectations, with examples including certain third-party sharing, downloading photos or contact lists, and location tracking
  • The collection, use or disclosure creates a meaningful residual risk of significant harm

Schedule 1 itself illustrates the older, broader range of acceptable forms. Clause 4.3.7 gives four examples of ways consent can be given, including a check-off box for asking that names and addresses not be passed to other organizations, with anyone who leaves it unticked assumed to consent to the transfer, oral consent by telephone, and consent at the time a product or service is used.

Inappropriate Purposes: the No-Go Zones

The consent guidelines close by reminding readers that consent is not a free pass, and point to a companion document published the same day, the OPC's Guidance on inappropriate data practices. Unlike the consent guidelines, that document is the federal office's alone. It interprets subsection 5(3), which limits collection, use and disclosure to purposes a reasonable person would consider appropriate in the circumstances, and lists the factors from Turner v. Telus Communications: the sensitivity of the information, whether the purpose represents a legitimate need, whether the practice would be effective, whether less invasive means exist at comparable cost and benefit, and whether the loss of privacy is proportional to the benefit.

It then identifies six purposes the OPC generally considers offside PIPEDA from a reasonable person's perspective:

  1. Collection, use or disclosure that is otherwise unlawful, with examples from credit reporting law and the Genetic Non-Discrimination Act
  2. Profiling or categorization that leads to unfair, unethical or discriminatory treatment contrary to human rights law
  3. Collection, use or disclosure for purposes known or likely to cause significant harm to the individual
  4. Publishing personal information with the intended purpose of charging individuals for its removal
  5. Requiring passwords to social media accounts for the purpose of employee screening
  6. Surveillance through the audio or video functionality of the individual's own device

The document says the list may evolve, and footnote 10 leaves room for exceptional cases in which contextual factors make a listed use appropriate. Its page records no modification since 24 May 2018.

Consent and Children

This is the section where the three signatories visibly part. The OPC takes the position that, in all but exceptional circumstances, anyone under the age of 13 cannot give meaningful consent, so consent must come from a parent or guardian. The Alberta and British Columbia commissioners, along with Quebec's Commission, set no specific age threshold and instead ask whether the individual understands the nature and consequences of exercising the right in question. For minors who can consent, the guidelines state that consent is meaningful only if the organization has reasonably taken their level of maturity into account in designing the process.

Alberta's statute writes a version of the provincial approach into law. Section 61 of the Alberta Personal Information Protection Act allows a person under 18 to exercise their own rights and powers under the Act if they understand the nature of the right or power and the consequences of exercising it, and otherwise lets a guardian do so.

Withdrawal, and What Consent Does Not Waive

The final section adds two points. Withdrawal of consent should stop further collection and use, and may mean deletion, with retained "do not contact" lists and legally required retention given as limits. And consent does not waive an organization's other obligations, such as accountability, collection limitation and safeguards: in the guidelines' words, an organization handling information contrary to legal requirements would still be in contravention even if the individual had consented.

Frequently Asked Questions

Are the OPC's meaningful consent guidelines legally binding?
They are guidance, not a regulation. The guidelines describe their "must" items as obligations arising from legal requirements and their "should" items as recommended best practices, which is the regulators' reading of the statutes. The binding text is PIPEDA itself, including clause 4.3 of Schedule 1 and section 6.1, and the substantially similar provincial Acts.
What are the four key elements the consent guidelines say must be emphasised?
What personal information is being collected; with which parties it is being shared; for what purposes it is collected, used or disclosed; and the risk of harm and other consequences. The guidelines say these must be emphasised up front, while complete information remains readily available for those who want to read it in full.
When do the guidelines say express consent is required under PIPEDA?
The guidelines list three situations in which organizations must generally obtain express consent: when the information is sensitive, when the collection, use or disclosure is outside the individual's reasonable expectations, and when it creates a meaningful residual risk of significant harm. PIPEDA's own clause 4.3.6 phrases the sensitivity point as something an organization "should generally" do.
What age does the OPC treat as too young to consent?
The OPC's position is that, in all but exceptional circumstances, anyone under 13 cannot provide meaningful consent, so a parent or guardian must consent. The Alberta and British Columbia commissioners do not set a specific age and look instead at whether the individual understands the nature and consequences of exercising the right in question.
What are the OPC's no-go zones?
They are six purposes the OPC's 2018 guidance on subsection 5(3) generally considers inappropriate regardless of consent: otherwise unlawful processing; profiling leading to unfair, unethical or discriminatory treatment contrary to human rights law; purposes known or likely to cause significant harm; publishing information to charge for its removal; requiring social media passwords for employee screening; and surveillance through an individual's own device's audio or video functions.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.