What it is
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law, enacted in 2000 and brought into force in stages from 2001 to 2004. Part 1 governs how organizations collect, use and disclose personal information in the course of commercial activity. The rules are built on ten fair information principles drawn from a national standard and set out in Schedule 1 to the Act.
Who it applies to
PIPEDA applies to private-sector organizations that collect, use or disclose personal information in the course of commercial activity, and to federal works, undertakings and businesses (such as banks, airlines and telecommunications companies) in respect of their employees' information. It does not apply to government institutions covered by the Privacy Act, to individuals acting for personal purposes, or to certain journalistic, artistic or literary activity. In provinces with their own "substantially similar" private-sector laws (Alberta, British Columbia and Quebec), those laws apply to most intra-provincial activity, while PIPEDA still covers cross-border flows of personal information and federally regulated organizations.
Core principles
Schedule 1 sets out ten principles: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance. Organizations must designate someone accountable for compliance, collect only what is needed for purposes they identify, and use personal information only for those purposes unless they obtain fresh consent.
Consent
Consent is the central legal basis. It must be meaningful, which means individuals understand what they are agreeing to, and it can be express or implied depending on the sensitivity of the information and reasonable expectations. The Act lists limited situations where consent is not required, such as certain legal, emergency and investigative circumstances. Individuals can generally withdraw consent, subject to legal and contractual restrictions.
Individual rights
Individuals have the right to be informed about an organization's practices, to access their personal information and challenge its accuracy and completeness, and to have it amended where appropriate. They can also withdraw consent and file complaints with the Privacy Commissioner. PIPEDA does not contain a general right to erasure or data portability comparable to those in the GDPR.
Key obligations
Organizations must implement safeguards appropriate to the sensitivity of the information, publish clear information about their policies and practices, respond to access requests, and limit retention. When transferring personal information to a third party for processing, including outside Canada, the organization remains responsible for it and must use contractual or other means to provide a comparable level of protection. Transparency about such transfers is expected.
Data breaches
Organizations must report to the Office of the Privacy Commissioner of Canada (OPC) any breach of security safeguards involving personal information under their control where it is reasonable to believe the breach creates a real risk of significant harm. Affected individuals must be notified, and the report and notice must be made as soon as feasible after the organization determines that a breach occurred. Organizations must also keep a record of every breach of security safeguards, whether or not it was reported, for a period set by regulation.
Enforcement and penalties
The OPC investigates complaints and can audit organizations, but it works on an ombudsman model and cannot itself issue orders or fines. After an investigation, the Commissioner or the complainant can apply to the Federal Court, which can order compliance and award damages. Fines are reserved for specific offences, such as knowingly failing to report a breach or obstructing the Commissioner, and are limited to a maximum of 100,000 dollars for the most serious cases. Proposed reforms to strengthen enforcement have not been enacted.
The official text
The authoritative version is the Personal Information Protection and Electronic Documents Act published by the Department of Justice on the Justice Laws website, in English and French, both of which are official. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English and French, both official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →