PIPEDA — the Personal Information Protection and Electronic Documents Act — is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activities.
Who PIPEDA Applies To
PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities. This includes most businesses operating in Canada, regardless of size. Federal works, undertakings, and businesses (banks, airlines, telecommunications companies) are subject to PIPEDA regardless of province.
Quebec, Alberta, and British Columbia have substantially similar provincial privacy laws that apply to provincially regulated organizations in those provinces.
The Ten Principles
PIPEDA is built on ten fair information principles derived from the CSA Model Code: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Since 2018, PIPEDA requires organizations to report breaches of security safeguards that create a real risk of significant harm to individuals. Breaches must be reported to the Office of the Privacy Commissioner of Canada and affected individuals must be notified.
Individual Rights Under PIPEDA
- The right to know what personal information an organization holds about you
- The right to access that information
- The right to challenge its accuracy
- The right to withdraw consent
- The right to complain to the Privacy Commissioner
PIPEDA and Bill C-27
The federal government has proposed replacing PIPEDA with the Consumer Privacy Protection Act (CPPA) through Bill C-27. This proposed legislation would strengthen privacy rights, increase penalties, and introduce new requirements around automated decision-making.
Complete the path with Privacy Best Practices.