PIPEDA compliance: what Canadian companies must do
PIPEDA is the federal privacy law most Canadian companies fall under. It is not a certification, there is nothing to pass, and it applies whether or not a customer ever asks about it.
The Personal Information Protection and Electronic Documents Act has been in force since 2001 and applies to private-sector organizations that collect, use or disclose personal information in the course of commercial activity. Unlike SOC 2 or ISO 27001, nobody audits you against it by default and there is no report at the end. It is simply the law, and the first time most companies think seriously about it is after a breach or during a customer's privacy review.
Does PIPEDA apply to your company
Start by ruling it out, because for a meaningful number of Canadian companies a provincial statute applies instead.
Three provinces have private-sector privacy laws that the federal government has declared substantially similar to PIPEDA. In those provinces, the provincial law governs organizations operating within the province, and PIPEDA steps back.
| Situation | Law that applies |
|---|---|
| Operating in Quebec | Law 25, the modernized Quebec private-sector regime |
| Operating in British Columbia | PIPA (BC) |
| Operating in Alberta | PIPA (Alberta) |
| Operating anywhere else in Canada | PIPEDA |
| Personal information crossing a provincial or national border | PIPEDA, regardless of province |
| Federally regulated business (bank, telecom, airline, interprovincial transport) | PIPEDA, including for employee information |
The part people miss
PIPEDA continues to apply to personal information that crosses a provincial or national boundary, even for a company based in BC, Alberta or Quebec. A Vancouver company with customers in Ontario, or one using a cloud region in the United States, is generally in scope for both the provincial law and PIPEDA. In practice you build one program that satisfies the stricter of the two.
Note also that PIPEDA covers employee personal information only for federally regulated businesses. For everyone else, employee data sits outside PIPEDA, which surprises companies that assumed one policy covered staff and customers alike.
The ten principles you are actually being measured against
PIPEDA's substance lives in Schedule 1, which sets out ten fair information principles. They are written as obligations, not suggestions, and a complaint to the Privacy Commissioner will be assessed against them.
| Principle | What it means in practice |
|---|---|
| Accountability | A named individual is responsible for privacy. Not a committee, a person. |
| Identifying purposes | You say why you are collecting something before or when you collect it. |
| Consent | Meaningful consent. Sensitive information needs express consent, not a pre-ticked box. |
| Limiting collection | Collect only what the stated purpose requires. |
| Limiting use, disclosure and retention | Use it only for the stated purpose, and delete it when that purpose ends. |
| Accuracy | Keep it correct and current enough for the purpose. |
| Safeguards | Protection proportionate to sensitivity. This is where security controls attach. |
| Openness | Your practices are documented and available to anyone who asks. |
| Individual access | People can ask what you hold about them and have errors corrected. |
| Challenging compliance | There is a route to complain to you, and it is published. |
The two that generate the most complaints are individual access and retention. Access requests carry a response deadline and a company with no process usually misses it. Retention is where most companies are quietly offside, because deleting data requires deciding what the purpose was and when it ended, and almost nobody does that at the point of collection.
Breach reporting is mandatory and has two separate duties
Since November 2018, PIPEDA has required organizations to deal with breaches of security safeguards in a specific way. This is the part with real teeth, and it is frequently misunderstood as one obligation when it is two.
Report and notify, if the threshold is met. Where a breach creates a real risk of significant harm to an individual, you must report it to the Office of the Privacy Commissioner, notify the affected individuals, and notify any other organization that may be able to reduce the harm. Significant harm includes humiliation, damage to reputation or relationships, identity theft, fraud, loss of employment or business opportunity, and financial loss. The assessment turns on the sensitivity of the information and the probability of misuse.
Record every breach, whether or not the threshold is met. This one gets missed. You must keep a record of every breach of security safeguards for 24 months, including the ones you assessed as low risk and did not report. The Commissioner can ask for those records, and being unable to produce them is itself the problem.
Knowingly failing to report or to keep records, or obstructing an investigation, carries fines of up to $100,000 CAD. Worth knowing about enforcement generally: the Commissioner operates on an ombudsman model, issuing findings and recommendations rather than penalties directly, with matters escalating to the Federal Court. Reform to add direct order-making and administrative monetary penalties has been introduced in Parliament more than once and has not been enacted, so check the current position before relying on it either way.
What compliance actually looks like
There is no certificate, so "being PIPEDA compliant" means being able to show a regulator or a customer the following, and having it be true.
- A named privacy officer, with the role written into someone's actual job.
- A privacy policy that describes what you really do, published where people can find it.
- A record of what personal information you hold, where it lives, and why. Most companies find this the hardest item and the most useful one.
- A retention schedule with deletion that happens, not just a documented intent to delete.
- A documented process for access requests, with an owner and a deadline.
- A breach response process that covers both the assessment and the 24 month record, with a log that already exists before you need it.
- Contracts with any vendor that touches personal information on your behalf. Accountability stays with you when you transfer data to a processor.
- Safeguards proportionate to sensitivity, which is where SOC 2 or ISO 27001 work becomes reusable.
What it costs
PIPEDA has no audit fee, because there is no audit. The cost is the work. For a company that already has security controls in place, a first pass at a privacy program is usually $8,000 to $25,000 CAD of external help, or a few weeks of internal effort if someone owns it properly. A privacy impact assessment for a specific product or data flow is typically $5,000 to $15,000 CAD.
Quebec companies should budget more. Law 25 requires privacy impact assessments in defined circumstances, adds its own breach duties, and carries penalties that reach into the millions or a percentage of worldwide turnover. It is the most demanding private-sector privacy regime in the country and it should be scoped separately rather than assumed to be covered by PIPEDA work.
How this relates to SOC 2 and ISO 27001
PIPEDA tells you how you may handle personal information. SOC 2 and ISO 27001 give a customer independent evidence that your controls work. They are not substitutes for each other, and a procurement team asking for a SOC 2 report will not accept a privacy policy in its place.
They do overlap usefully. The safeguards principle is satisfied largely by the same access control, encryption, logging and vendor management work that a SOC 2 engagement requires, and the ISO 27001 Annex A control set covers most of it as well. If you are doing both, do the data inventory first. It is the input to a retention schedule, a privacy impact assessment and an audit scope alike, and doing it once saves repeating it three times.
Not sure where you stand on PIPEDA
Tell us what you handle and who is asking. We will tell you which law applies to you and what the gap looks like.
Get matchedCommon questions
Is there such a thing as PIPEDA certification?
No. PIPEDA is legislation, not a standard, and no body certifies against it. Any vendor selling you a PIPEDA certificate is selling you something that does not exist. What you can get is an assessment against the ten principles, which produces a gap report rather than a certificate.
Can we store Canadian personal information in the United States?
Generally yes. PIPEDA does not require data to stay in Canada. It does require that accountability follows the data, so you remain responsible for it and must use contractual means to give it comparable protection. Some provincial public-sector rules and some customer contracts do impose residency requirements, so the constraint usually arrives through a contract rather than through PIPEDA itself.
Do we need consent for everything?
You need meaningful consent for collection, use and disclosure, with the form of consent scaled to sensitivity. Express consent is expected for sensitive information. There are defined exceptions, including some business transactions and investigations. The practical test is whether a reasonable person would consider the purpose appropriate, which is a separate requirement that consent alone does not satisfy.
How long do we have to respond to an access request?
Thirty days from receipt, with a limited ability to extend in defined circumstances and an obligation to tell the individual if you do. Charging a fee requires telling the person the approximate cost first and getting their agreement to proceed.
We are a small company. Does PIPEDA still apply?
Yes. There is no revenue or headcount threshold. What scales with size is what counts as reasonable: the safeguards expected of a company of five are not those expected of a bank. The obligations themselves do not disappear.