Skip to content

What Is PIPEDA? Canada's Privacy Law Explained (2026) | Enzuzo

Osman Husain 9/14/26, 10:42 PM
pipeda

Table of Contents

PIPEDA is Canada's federal privacy law. It sets the rules for how businesses collect, use, and disclose personal information during commercial activity. The Office of the Privacy Commissioner of Canada is tasked with PIPEDA enforcement and rollout.

Most businesses that handle the personal information of people in Canada answer to PIPEDA, either directly or the moment their data crosses a provincial border. The law applies to everything from a one-person online store to a national telecom. It rests on ten principles, one regulator, and a definition of personal information broad enough to include an IP address.

What does PIPEDA stand for?

PIPEDA stands for the Personal Information Protection and Electronic Documents Act (its full form). It became law in 2000, and the name covers two jobs. Part 1 is the privacy law businesses mean when they say PIPEDA; Part 2 lets federal law accept electronic documents and signatures in place of paper.

The full statute is published by the Department of Justice. Its stated purpose is to balance a person's right to privacy against a business's need to use personal information for purposes a reasonable person would consider appropriate as outlined in section 3.

See the PIPEDA compliance checklist for the full analysis of how to be compliant.

Who does PIPEDA apply to?

PIPEDA applies to private sector organizations that handle personal information during commercial activity across Canada. A commercial activity is "any transaction or conduct of a commercial character, including selling or leasing a membership or fundraising list' (section 2 has all the details).

Three groups are always in scope:

  • Businesses whose personal information crosses a provincial or national border, which covers most online stores and any company with customers in more than one province.
  • Federally regulated businesses, such as banks, airlines, railways, and telecom companies. PIPEDA also covers these employers' handling of their own employees' information.
  • Organizations in Yukon, the Northwest Territories, and Nunavut, which are treated as federally regulated.

Alberta, British Columbia, and Quebec have their own privacy laws deemed substantially similar to PIPEDA, so for personal information handled entirely within one of those provinces, the provincial law generally applies.

Ontario, New Brunswick, Nova Scotia, and Newfoundland and Labrador have substantially similar rules for personal health information only. Information that crosses a provincial or national border stays under PIPEDA regardless of provincial origin.

A foreign business can also fall under PIPEDA. When an organization outside Canada has a real and substantial connection to Canada, such as selling to Canadian customers and handling their data, PIPEDA will likely apply.

The same accountability follows personal information a Canadian business sends abroad for processing; see the cross-border data transfer breakdown for more details. 

 

2-coverage-3b-decision@3x

Is PIPEDA a federal or provincial law?

PIPEDA is a federal law, passed by Parliament and applied nationwide. It sets a national baseline for private-sector privacy.  Provincial law governs only in Alberta, British Columbia, and Quebec, which have similar privacy laws that supersede it.

A business can answer to a provincial law day to day and still fall under PIPEDA the moment its data crosses a border.

For example:

A Vancouver skincare shop. Day to day, it signs up BC customers, emails them, and stores their details on a Canadian server. All of that handling happens inside British Columbia, so it answers to BC's Personal Information Protection Act (PIPA), the province's substantially similar law. PIPEDA sits in the background.

Then the shop opens online sales to customers in Ontario and Alberta and moves its email list to a U.S. platform. Two borders just got crossed: customer data flowing out to other provinces, and data sent to a provider in another country. Those cross-border flows fall under PIPEDA, even though the shop is physically in Vancouver, with most of its  day-to-day sales falling under BC's PIPA.

 

What are the 10 principles of PIPEDA?

The 10 principles of PIPEDA are the fair information principles in Schedule 1 of the Act, and the core obligations of the Act flow from them. A few obligations come from elsewhere in the Act, including mandatory breach reporting, added in 2018.

The 10 PIPEDA principles at a glance
Principle What it requires Example
1. Accountability Put someone in charge of privacy, and stay responsible for data you hand to a vendor Name a privacy officer whose contact details are public
2. Identifying purposes Decide and record why you collect each piece of data, before you collect it State on the signup form why a birthdate is needed
3. Consent Get knowledge and consent to collect, use, or disclose, with stronger consent for sensitive data Ask for opt-in before using health information
4. Limiting collection Collect only what the purpose needs, by fair and lawful means Don't ask for a social insurance number to run a newsletter
5. Limiting use, disclosure, and retention Use data only for the purpose you collected it for, and keep it only as long as needed Delete abandoned-cart records on a schedule
6. Accuracy Correct and complete enough that decisions made from the data are sound Let a customer fix a wrong shipping address
7. Safeguards Protect data with security matched to its sensitivity Encrypt stored payment details
8. Openness Publish how you handle personal information, in language a customer can follow Publish a plain-language privacy policy
9. Individual access Let people see what you hold and correct mistakes, at minimal or no cost Answer an access request within 30 days
10. Challenging compliance Give people a way to complain, and investigate every complaint Route privacy complaints to your privacy officer

 

What is personal information under PIPEDA?

Personal information under PIPEDA is any information about an identifiable individual. That covers obvious identifiers such as a name, address, income, or ID number, and, per the OPC's examples, less obvious data such as opinions, employee files, and credit, loan, or medical records. An IP address or device identifier can count too when it points to a person.

Sensitivity depends on context. Medical and financial information, such as income, credit, or payment records, is almost always sensitive, but context decides the rest (Schedule 1, 4.3.4). The statute's example: a newsmagazine's subscriber list is usually not sensitive; a special-interest magazine's can be. The more sensitive the information, the stronger the consent and safeguards it needs.

Business contact information is the one category the law excludes by design: a name, title, business address, phone number, or work email used solely to reach someone in their professional capacity (section 4.01). Sell or rent that same contact list, and PIPEDA applies to every address on it.

 

3-personal-info-4a-zones@3x

When can a business use personal information without consent?

PIPEDA lists narrow cases where a business can collect, use, or disclose personal information without knowledge or consent (section 7). The main ones:

  • complying with a subpoena, warrant, or other legal requirement
  • collecting a debt the person owes you
  • investigating a suspected breach of an agreement or the law, where asking would tip off the subject
  • an emergency that threatens someone's life, health, or security
  • publicly available information of the kinds named in the regulations

Parties to a merger or acquisition can also share personal information under a confidentiality agreement while they assess the deal (section 7.2). Outside these cases, consent is the default.

Enzuzo helps businesses obtain and store proof of consent, enabling seamless PIPEDA compliance. Book a call with a privacy expert to learn more about how it works. 

 

What does PIPEDA not cover?

PIPEDA doesn't cover federal government institutions, which answer to the Privacy Act, nor provincial or territorial governments. It also leaves out several kinds of activity:

  • an individual's collection or use of personal information for purely personal reasons, such as a personal greeting-card list
  • an organization's collection or use of personal information solely for journalistic, artistic, or literary purposes
  • business contact information used only for work contact

Not-for-profits, charities, and political parties usually fall outside PIPEDA unless they engage in commercial activity, such as selling merchandise. Municipalities, universities, schools, and hospitals usually fall under provincial law, though PIPEDA can apply in some cases.

 

Who enforces PIPEDA?

PIPEDA is enforced by the Office of the Privacy Commissioner of Canada. It isn't enforced by the Competition Bureau, a common mix-up: the Competition Bureau handles competition and misleading-advertising law, so privacy complaints go to the Privacy Commissioner instead. The Commissioner is an Agent of Parliament who investigates complaints, audits organizations, and reports findings.

The Commissioner can't levy fines under the current law. An investigation ends in findings and recommendations (section 13); if a business ignores them, the complainant or the Commissioner can ask the Federal Court to order changes and award damages (section 16).

The only fines, up to $100,000, come from a court prosecuting the specific offences in section 28, such as knowingly failing to report a breach. The PIPEDA penalties guide covers how enforcement works in practice.

 

What rights do individuals have under PIPEDA?

Under PIPEDA, a person can ask what personal information a business holds about them, how it has been used, and who it has been shared with, and receive a copy.

They can challenge information that is wrong and have it corrected. They can withdraw consent, subject to legal or contractual limits and reasonable notice. And they can complain, first to the organization and then to the Office of the Privacy Commissioner of Canada.

PIPEDA's rights are narrower than the GDPR's. There is no general right to erasure and no data-portability right in the current law, though Bill C-36 would add both. 

 

4-rights-5b-dark@3x

When did PIPEDA come into effect?

PIPEDA became law in 2000 and was phased in over four years. Part 1 first applied on January 1, 2001 to federally regulated businesses and to personal information sold across provincial or national borders, then extended to all commercial activity across Canada on January 1, 2004 (section 30).

Later amendments came mainly through the Digital Privacy Act of 2015, which added the mandatory breach-reporting rules that took effect on November 1, 2018.

 

Where does PIPEDA reform stand (Bill C-36)?

PIPEDA is mid-reform. The live bill is Bill C-36, the Protecting Privacy and Consumer Data Act, introduced on June 15, 2026 and, as of September 2026, sitting at first reading, so PIPEDA remains the law until it passes.

It succeeds Bill C-27, which carried the Consumer Privacy Protection Act (CPPA) and died when Parliament was prorogued in January 2025. Bill C-11 met the same fate in 2021, making C-36 the third reform attempt since 2020.

If Bill C-36 becomes law, it would repeal Part 1 of PIPEDA and replace it with a new private-sector privacy law. Three changes matter most for businesses:

  • Much larger penalties. Administrative penalties up to the higher of $10 million or 3% of global revenue, and offence fines up to the higher of $25 million or 5%, far above today's $100,000 cap.
  • A new regulator. A Digital Safety and Data Protection Commission of Canada would take over private-sector oversight from the Office of the Privacy Commissioner.
  • New rights. A right to have data deleted, a data-portability right, and stronger protections for children's information.

Bill C-36 is a privacy bill only. Unlike Bill C-27, it doesn't include an artificial intelligence act.

 

reform-6a-horizontal@3x

 

PIPEDA vs other privacy laws

PIPEDA is often called Canada's GDPR equivalent, and the comparison is fair in spirit but loose in detail. Both are consent-based and cover a broad range of personal information, but the GDPR grants more rights and carries far heavier fines.

Provincial laws such as Quebec's Law 25 and health-privacy laws such as Ontario's PHIPA apply alongside PIPEDA within their own provinces. How PIPEDA compares with the GDPR, HIPAA, PHIPA, and the provincial PIPA laws gets its full breakdown.

 

Enzuzo enables PIPEDA compliance

Enzuzo's consent management platform records what each website visitor agreed to and when, and its data request form gives people a route to ask what you hold. Those cover the consent and access side of PIPEDA.

 

Frequently asked questions

What does PIPEDA mean?

PIPEDA means the Personal Information Protection and Electronic Documents Act. In plain terms, it's the rulebook for how Canadian businesses handle personal information: collect it for a stated reason, get consent, protect it, and let people see it. It applies to commercial activity and rests on ten fair information principles in Schedule 1.

Who does PIPEDA apply to outside Canada?

A business based outside Canada can fall under PIPEDA when it has a real and substantial connection to Canada: targeting Canadian customers, collecting their data, or moving it across the border. Being incorporated abroad doesn't on its own put a company beyond PIPEDA's reach if it handles the data of people in Canada.

Does PIPEDA apply to non-profits?

PIPEDA generally applies to non-profits and charities only when they carry on a commercial activity that is not central to their mandate, such as selling merchandise or leasing a membership list. A charity's core, non-commercial handling of member or donor information typically falls outside PIPEDA, though provincial law may still apply.

Is PIPEDA the same as GDPR?

No, PIPEDA and the GDPR aren't the same, though they share a consent-based, principles-based approach, and the EU recognizes Canada as providing adequate protection for data transfers. But the GDPR grants broader rights, such as erasure and portability, and its fines run far higher than PIPEDA's $100,000 ceiling. PIPEDA vs GDPR has the full comparison.

Osman Husain

Osman Husain

Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.