PIPEDA compliance, for people who run a business rather than a legal department
JF
By James Frost, Founder, WARDORX
Last reviewed
31 min read
The ten principles in plain English, a 32-point self-audit you can finish this afternoon, three templates you can fill in, and an honest account of what actually happens when a Canadian business gets this wrong.
Before you start
Most guides to this subject open by telling you that Canadian privacy law can cost you millions. That claim is the reason this one exists, because it is not true, and a business owner who believes it ends up buying the wrong things.
The Personal Information Protection and Electronic Documents Act applies to almost every business in Canada that handles personal information as part of doing business. There is no revenue threshold and no employee-count exemption. A sole proprietor with a contact form is covered. What PIPEDA does not have is the thing everyone assumes it has: the Privacy Commissioner of Canada cannot fine you. The Commissioner investigates, publishes findings, and makes recommendations. That is the machinery.
The penalties people quote - up to 5% of global revenue - come from Bill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act and given the regulator real teeth. It died when Parliament was prorogued in January 2025 and has not been re-enacted since. Guides published in 2023 described it as imminent; a great many of them have never been updated.
So the honest version is this. Your regulatory fine risk under PIPEDA today is low. Your risk from a class action after a breach is not - the largest Canadian privacy settlements have come from civil litigation, not regulators. Your risk under CASL, which the CRTC enforces with actual collected penalties, is real and immediate. Your risk under Quebec's Law 25 is real if you have a single Quebec customer. And the cost of a published adverse finding, for a business whose customers are choosing whether to trust it, is not measured in dollars at all.
This guide covers what the law actually requires, gives you a self-audit you can complete without hiring anyone, and hands you three templates to fill in. It is long. Use the contents to jump to the part you need.
The lifecycle PIPEDA describes
Most compliance work is stage four. Data deleted on schedule cannot appear in a breach, be produced in an access request, or be argued about in a class action.
The breach test
Real risk of significant harm
Two factors decide it: how sensitive the information was, and the probability it has been, is being, or will be misused. If both point to harm, you report to the Commissioner and notify the individuals as soon as feasible.
There is no 72-hour clock in PIPEDA - that is GDPR. What PIPEDA has instead is a standard you have to be able to defend, which is why the assessment gets written down either way.
Jump to
Section 01
What PIPEDA actually requires
Ten principles, one statute, and a scope that catches more businesses than people expect.
PIPEDA applies to organizations that collect, use or disclose personal information in the course of commercial activities. Personal information means information about an identifiable individual - which is broader than a name and an email, and includes anything that could reasonably be combined with other available information to identify someone. An IP address, a device identifier and a purchase history all qualify in the right circumstances.
The Act also applies to personal information about employees, but only of federal works, undertakings and businesses: banks, airlines, telecommunications companies, railways, interprovincial trucking and broadcasting. For everyone else, employee privacy is provincial.
When a provincial law applies instead
Alberta, British Columbia and Quebec have private-sector privacy laws declared substantially similar to PIPEDA, and within those provinces the provincial statute governs organizations operating there. Several provinces have health-specific legislation that has also been declared substantially similar for health custodians. This does not get you out of PIPEDA: the federal Act continues to apply to personal information crossing provincial or national borders in commercial activity, which for any business with a website is most of it.
The ten principles below come from Schedule 1 of the Act, which incorporates the CSA Model Code for the Protection of Personal Information. They are drafted as obligations, and the clause numbers are given so you can read the original wording rather than take anyone's summary on faith.
01Schedule 1, 4.1
Accountability
One named person is responsible, and you can say who.
PIPEDA requires you to designate an individual accountable for the organization's compliance, and to make that person's identity available on request. It also makes you responsible for personal information you hand to a third party for processing - your payroll provider, your CRM, your email platform - which you are expected to cover by contractual or other means. Outsourcing the work never outsources the accountability.
How it breaks: A five-person shop signs up for four SaaS tools, each holding customer records, and nobody can name who approved them or what they are allowed to do with the data.
02Schedule 1, 4.2
Identifying Purposes
Decide why you are collecting something before you collect it, and write it down.
The purposes must be identified at or before the time of collection. If you later want to use the information for something new, that is a new purpose and it needs fresh consent. The practical test is whether a person handing you their phone number would recognise everything you go on to do with it.
How it breaks: You collect phone numbers for appointment reminders, then two years later load the same list into an SMS marketing tool because it was sitting there.
03Schedule 1, 4.3
Consent
People have to know what they are agreeing to, and agree to it knowingly.
Consent is only valid if it is reasonable to expect the individual understood what they were agreeing to. The joint guidance from the federal, Alberta and BC commissioners sets out what someone must be able to understand: what is being collected, who it is shared with, the purposes, and the risk of harm. Sensitive information needs express consent. You also cannot make consent to unnecessary collection a condition of service.
How it breaks: A checkout page with a pre-ticked box that says “I agree to the terms”, where the terms bury the sale of browsing data to an ad network on page nine.
04Schedule 1, 4.4
Limiting Collection
Collect what you need for the stated purpose. Nothing else.
Collection is limited to what is necessary for the identified purposes, and it must be by fair and lawful means. In practice this is the principle that catches the form with fourteen fields on it. Every field you cannot tie to a stated purpose is a liability with no matching benefit - you carry the breach risk without getting anything for it.
How it breaks: A quote form asking for date of birth and annual income because the template came that way.
05Schedule 1, 4.5
Limiting Use, Disclosure and Retention
Use it only for what you said, and throw it away when you are done.
Information must not be used or disclosed for purposes other than those it was collected for, except with consent or as required by law, and it must be retained only as long as necessary to fulfil those purposes. You are required to have guidelines and procedures covering retention periods, including minimum and maximum. Data you deleted on schedule cannot appear in a breach.
How it breaks: A CRM holding every enquiry since 2014, including people who never became customers, because storage is cheap and nobody set a rule.
06Schedule 1, 4.6
Accuracy
Keep it correct enough for what you are using it for.
Information must be as accurate, complete and up to date as is necessary for the purposes for which it is used. The bar scales with the stakes: a mailing address for a newsletter and a mailing address used to decide whether someone gets a service are not held to the same standard. Notably, you are not expected to routinely update information unless doing so is necessary to fulfil the purposes.
How it breaks: A stale address record that sends someone else's invoice, containing their name and balance, to a previous tenant.
07Schedule 1, 4.7
Safeguards
Protect it in proportion to how sensitive it is.
Security safeguards must be appropriate to the sensitivity of the information, and PIPEDA names three kinds: physical, organizational and technological. Organizational means access controls and who is allowed to see what. It is the one small businesses skip, and it is the one that shows up in the findings - most Canadian insider-breach cases are a story about an employee who had access they did not need.
How it breaks: Everyone in the company shares one admin login to the booking system, so an export at 2am cannot be attributed to anyone.
08Schedule 1, 4.8
Openness
Your privacy practices have to be findable and readable.
You must make specific information about your policies and practices readily available in a form that is generally understandable. That includes the name and address of the person accountable, how to get access to your information, what you hold and what it is used for, and what is made available to related organizations. “Readily available” does not mean it exists somewhere; it means a person can find it without asking.
How it breaks: A privacy policy that only appears after account creation, or one written by copying a US template that references California.
09Schedule 1, 4.9
Individual Access
On request, tell someone what you hold and let them correct it.
On written request, an individual must be told whether you hold personal information about them, what it is used for, and to whom it has been disclosed - and be given access to it. You have thirty days to respond, extendable in limited circumstances if you notify them within the original thirty. Access must be at minimal or no cost, and you must tell them the cost before proceeding. Refusals must state reasons and the recourse available.
How it breaks: A request lands in a generic inbox in July, nobody recognises it as an access request, and the clock runs out before anyone reads it.
10Schedule 1, 4.10
Challenging Compliance
There has to be a way to complain to you, and you have to investigate.
An individual must be able to address a challenge concerning compliance to the accountable person. You are required to have procedures to receive and respond to complaints, to make them easily accessible and simple to use, and to investigate all complaints received. Where a complaint is found to be justified, you must take appropriate measures - including amending your policies if that is what it takes.
How it breaks: A complaint answered with “our policy is our policy” and no record that it was ever investigated.
Section 02
The 32-point self-audit
Work through it once, honestly. Anything you cannot tick is a decision you have not made yet.
Every item traces to one of the ten principles, so this is not a list somebody invented to look thorough. Tick what is true today, not what you intend to do. Your progress is saved in this browser only - nothing is sent anywhere, which is the least we can do on a page about data minimisation.
0/32
Saved in this browser only. Nothing is sent anywhere.
Accountability and governance
0/6
Who is responsible, and can you prove it on a Tuesday afternoon with no notice.
Knowing what you hold
0/5
You cannot limit, secure or delete data you have never inventoried.
Consent and notice
0/6
The part that gets small businesses caught, because the defaults are wrong.
Safeguards
0/7
Proportionate to sensitivity - which means a clinic and a landscaper differ.
Individual rights
0/4
Thirty days is shorter than it sounds when nobody is watching the inbox.
Breach readiness
0/4
The obligations here are the only part of PIPEDA carrying an offence provision.
Section 03
Three templates to fill in
A privacy policy, a cookie policy and a breach response plan. Bracketed fields are yours.
These are starting points shaped for a Canadian small business, not finished legal documents. The most common way a template hurts you is by describing controls you do not have: a policy claiming role-based access and annual training becomes evidence against you if a regulator asks to see either. Delete what is not true.
Privacy policy
Structured around the ten principles, because that is the order an investigator reads in.
Where it goes: Publish at /privacy and link it from the footer of every page and beside every form. Replace every bracketed field. Delete any section describing something you do not actually do - an aspirational policy is worse than a short one, because it documents a practice you are then failing to follow.
Cookie policy
The categories a consent banner has to match, written so a person can act on them.
Where it goes: Publish at /cookies. It only works if the banner actually gates what this page describes - a policy naming three categories in front of a banner that loads everything on arrival documents your own violation. Fill the table from a real scan of your site, not from memory.
Breach response plan
One page, because a plan nobody can read at midnight is not a plan. Covers the offence provisions.
Where it goes: Print it. Put a copy where someone can reach it without logging into the system that just failed. Fill in the phone numbers now - the point of this document is that it contains decisions already made.
Section 04
What differs by industry
The principles are the same everywhere. The way people break them is not.
Four sectors, chosen because each has a characteristic failure that generic advice misses. If you are in none of them, read the e-commerce section anyway - the marketing-stack problem it describes is close to universal.
E-commerce and retail
Your checkout is fine. Your marketing stack is the problem.
Almost every Canadian e-commerce privacy failure is the same shape: data collected legitimately for a transaction gets piped into an advertising platform for a purpose the customer never agreed to. Conversions APIs, offline event uploads and audience matching all take customer records and send them to a third party, and none of them are covered by the consent someone gave to have their order shipped. If you upload a customer list to build a lookalike audience, that is a disclosure, and it needs its own consent.
What to look at
Server-side tagging and conversions APIs, which move data without a browser cookie and are invisible to a cookie banner
Order confirmation emails that carry marketing tracking pixels
Abandoned-cart flows built on an email address collected before consent was given
Loyalty programs that quietly join in-store and online identities
Payment data you never needed to store because the processor already holds it
Also applies: CASL applies to every commercial electronic message, and the CRTC does levy real fines. Keep proof of consent for each address, including when and how it was obtained.
SaaS and technology
You are a processor for your customers and a controller for your own users.
The two roles have different obligations and SaaS companies routinely apply one policy to both. Data your customers put into your product is theirs; you handle it under contract and you should not be mining it for anything they did not agree to, including model training. Data about your customers - billing, support tickets, product analytics - is yours to account for. Where you sell into Quebec, the EU or California, your customers will push their own obligations onto you through the contract, so your data processing addendum becomes the document that decides your engineering roadmap.
What to look at
Product analytics and session replay capturing form fields containing customer data
Support tooling where every agent can read every account
Using customer data to train models without a specific, separate agreement
Sub-processors added by a vendor without notice flowing down to your customers
Free trials and demo environments seeded with real production data
Also applies: If you offer to EU residents or monitor their behaviour, GDPR applies regardless of where you are incorporated. Quebec Law 25 requires a privacy impact assessment before communicating personal information outside Quebec.
Healthcare and clinics
PIPEDA may not be your main statute, and that catches people out.
Health information is among the most sensitive categories there is, and several provinces have their own health privacy legislation that governs custodians - Ontario's PHIPA is the best known. Depending on where you practise and what you do, you may be under provincial health privacy law, PIPEDA, or both, and a clinic that assumes one federal statute covers everything usually discovers otherwise during an audit. Express consent is the baseline here, not the exception, and the safeguards bar rises with the sensitivity.
What to look at
Booking and reminder tools that put appointment reasons in an SMS or a calendar title
Reception screens and printers visible from the waiting area
Staff accessing records of people they know - the single most common health privacy complaint
Cloud storage or transcription vendors holding health data outside the province or country
Retention of records long past the period the professional college requires
Also applies: Check your provincial health privacy statute and your regulatory college's records requirements first. They are usually stricter than PIPEDA and they are the ones that will discipline you.
Financial services and insurance
You are probably federally regulated for employee data too.
PIPEDA covers commercial activity generally, but for federal works and undertakings - banks, and federally regulated sectors like airlines, telecommunications and interprovincial transport - it also covers employee personal information, which is otherwise a provincial matter. Financial information is sensitive by default, which raises both the consent standard and the safeguards standard, and the sector carries anti-money-laundering obligations that require you to collect and retain identity information you would otherwise be told to minimise. Those two pressures pull in opposite directions and the resolution has to be written down.
What to look at
Identity documents retained indefinitely because AML rules required collecting them
Brokers and agents holding client data in personal email or spreadsheets
Credit checks run without express consent for that specific purpose
Recorded calls that capture card numbers into a system nobody scoped as sensitive
Insider access to accounts of family, neighbours or public figures
Also applies: FINTRAC record-keeping obligations set retention floors that override your instinct to delete. Document where a legal obligation is the reason you are keeping something.
Section 05
What actually happens when it goes wrong
Real Canadian cases, with the outcomes stated accurately rather than dramatically.
PIPEDA does contain offences, and they are narrow. Knowingly failing to report a breach to the Commissioner, knowingly failing to notify affected individuals, knowingly failing to keep breach records, obstructing an investigation, or dismissing an employee who blew the whistle - those carry fines of up to $100,000 on indictment. They are prosecuted by the Crown, not levied by the Commissioner, and prosecutions are rare.
Everything else in the Act is enforced through investigation, published findings, compliance agreements, and applications to the Federal Court. That is a real cost when your customers can read the finding, and it is not a fine.
Home Depot of Canada
2023
Outcome OPC found a contravention. No fine - the Commissioner cannot levy one.
What happened
Customers asking for an emailed receipt at the till had encoded versions of their email address, plus details of their in-store purchase, sent to Meta for advertising measurement.
What went wrong
The practice was disclosed only in a privacy statement that customers were never shown at the till. Nobody asking for a receipt would have understood their purchase history was going to Facebook, which is the exact test meaningful consent applies.
The lesson
A disclosure that exists but is not encountered is not consent. If the moment of collection is a checkout counter, the explanation has to live at the checkout counter.
Tim Hortons
2022
Outcome Joint finding by the federal, Quebec, Alberta and BC commissioners. Recommendations accepted; data deleted. Separately, a class action settled for a free coffee and a baked good.
What happened
The mobile app collected granular location data continuously - not only when the app was open - inferring home and work locations and visits to competitors.
What went wrong
Users consented to location access for a stated purpose that did not match continuous tracking, and the purpose itself was found not to be one a reasonable person would consider appropriate.
The lesson
Permission granted to your app is not consent for every use you can technically make of it. And the reputational cost dwarfed the legal one - the settlement became a national punchline.
Clearview AI
2021
Outcome Joint finding of contravention. Clearview stopped offering its service in Canada but disputed the finding and declined to delete Canadians' images. The OPC could not compel it.
What happened
Billions of images were scraped from public websites and social media to build a facial recognition database sold to law enforcement.
What went wrong
Collection without consent, for a purpose the commissioners found inappropriate regardless of consent - some purposes are simply not available to you.
The lesson
This is the clearest illustration of the enforcement gap. A finding of contravention is not an order, and a company willing to absorb the reputational hit can decline to comply.
Desjardins
2020
Outcome OPC investigation found safeguard and accountability failures. The financial consequence came from a class action settlement and remediation costs, not a regulator.
What happened
An employee copied personal information on roughly 9.7 million individuals over more than two years and passed it outside the organization.
What went wrong
Access controls, monitoring and training - an employee had access far beyond their role, for a long time, without detection. This was an organizational safeguards failure, not a hacking story.
The lesson
The most expensive Canadian privacy incidents have been insider access problems. Least-privilege access and individual accounts cost nothing and are the control that would have shortened this by years.
CRTC anti-spam enforcement
2015 onward
Outcome Real, collected penalties: Compu-Finder was penalised $1.1 million; Rogers Media $200,000; Porter Airlines $150,000; Kellogg Canada $60,000.
What happened
Commercial electronic messages sent without valid consent, or without functioning unsubscribe mechanisms and required identification.
What went wrong
Consent was assumed from a business relationship that had lapsed, or never documented at all, and unsubscribe requests were not honoured within the required period.
The lesson
If you are budgeting for Canadian privacy risk, budget for CASL. It is the regime where a Canadian regulator writes a number on a page and collects it.
Section 06
PIPEDA vs Law 25 vs CCPA vs GDPR
Four regimes you may be under at once, and where they genuinely differ.
You do not choose which of these applies. They apply based on where the person is, and a single Canadian business with a public website can easily be under all four. The good news is that they overlap heavily: build to the strictest one that touches you and the others mostly come free.
The practical order to work in
Start with PIPEDA because it is your baseline and always applies. Add Law 25 next if you have any Quebec customers - it is the strictest regime in Canada, it has genuine penalties, and its privacy-officer and assessment obligations are structural rather than cosmetic. Add GDPR if you sell into Europe or monitor European visitors. Treat CCPA last unless you cross its revenue or volume thresholds, because most Canadian small businesses do not.
PIPEDA, Quebec Law 25, California CCPA and the EU GDPR compared across scope, penalties, consent, breach notification, individual rights, privacy officer and assessments.
Compare
PIPEDACanada, federalOPC investigates and recommends. It cannot levy fines. Federal Court can order remedies.
Quebec Law 25QuebecCAI can impose administrative monetary penalties. Private right of action with minimum punitive damages.
CCPA / CPRACaliforniaCPPA and the Attorney General assess civil penalties per violation.
GDPREU / EEASupervisory authorities issue binding fines and corrective orders.
Who it covers
Any private-sector organization handling personal information in commercial activity. No size or revenue threshold.
Any enterprise operating in Quebec, including sole proprietors. No size or revenue threshold.
For-profits meeting a threshold: revenue over roughly $25M, or 100,000+ consumers, or 50%+ of revenue from selling or sharing data.
Anyone processing EU residents' data while offering goods or services to them or monitoring their behaviour.
Maximum exposure
Up to $100,000 per offence, and only for specific offences such as knowingly failing to report a breach or obstructing an investigation.
Administrative penalties up to $10M or 2% of worldwide turnover; penal offences up to $25M or 4%.
$2,500 per violation, $7,500 if intentional or involving a consumer under 16. Counted per consumer.
Up to €20M or 4% of global annual turnover, whichever is higher.
Consent model
Knowledge and consent, express for sensitive information. Implied consent available in limited cases.
Consent must be clear, free, informed and given for specific purposes, separately from other terms.
Notice at collection plus a right to opt out of sale or sharing. Opt-in required for minors.
One of six lawful bases. Where consent is used it must be freely given, specific, informed and unambiguous.
Breach notification
Report to the OPC and notify individuals as soon as feasible where there is a real risk of significant harm. Records of all breaches kept 24 months.
Notify the CAI and affected individuals where there is a risk of serious injury. Maintain an incident register.
No general regulator notification duty under CCPA itself; California's separate breach statute applies, and breaches carry a private right of action.
Notify the supervisory authority within 72 hours where there is a risk to rights and freedoms.
Individual rights
Access and correction. No general right to deletion or portability.
Access, correction, de-indexing, cessation of dissemination, and data portability since September 2024.
Know, delete, correct, opt out of sale or sharing, limit use of sensitive information, non-discrimination.
Access, rectification, erasure, restriction, portability, objection, and rights around automated decisions.
Privacy officer
A designated accountable individual is required. No formal title mandated.
Mandatory; defaults to the person with the highest authority unless delegated in writing, and the title must be published.
Not required.
A Data Protection Officer is required for public bodies, large-scale monitoring, or large-scale sensitive data.
Assessments before new projects
Not mandated by statute. Expected as good practice for high-risk processing.
Privacy impact assessments required for information system projects and before transferring data outside Quebec.
Risk assessments and cybersecurity audits for higher-risk processing, under CPPA regulations.
Data protection impact assessment required where processing is likely to result in high risk.
Scroll the table sideways on a phone. Figures are maximums, not expected outcomes.
Questions
Does PIPEDA apply to my one-person business?
Almost certainly yes. PIPEDA applies to organizations that handle personal information in the course of commercial activity, and there is no exemption based on revenue, headcount or being a sole proprietor. What scales with your size is what counts as appropriate safeguards, not whether the principles apply. If you are in Alberta, BC or Quebec, the provincial statute may govern your activity within the province while PIPEDA continues to cover anything crossing a border.
Can the Privacy Commissioner fine me under PIPEDA?
No. The Office of the Privacy Commissioner of Canada investigates complaints, publishes findings, negotiates compliance agreements and can apply to the Federal Court, but it has no power to levy administrative monetary penalties under PIPEDA. There are offence provisions carrying fines up to $100,000, but those cover a narrow set of acts - knowingly failing to report or record a breach, obstructing an investigation, retaliating against a whistleblower - and they are prosecuted by the Crown. Bill C-27 would have changed this and it died in January 2025.
Do I need a cookie banner in Canada?
PIPEDA does not name cookie banners, but it does require knowledge and consent before collecting personal information, and analytics and advertising identifiers generally qualify. In practice that means non-essential trackers should not fire until the visitor agrees. The failure we see most often is not a missing banner - it is a banner that appears while the trackers have already loaded, which records nothing and creates a written record of the violation.
How long do I have to answer an access request?
Thirty days from receipt. You can extend by up to a further thirty days in limited circumstances - such as when meeting the deadline would unreasonably interfere with operations or more time is needed to convert the information - but you must notify the person of the extension, the reason and their right to complain, within the original thirty days. Access should be at little or no cost, and you must give a cost estimate before proceeding.
When do I have to report a data breach?
When a breach of security safeguards creates a real risk of significant harm to an individual, you must report it to the Commissioner and notify affected individuals as soon as feasible. Significant harm includes humiliation, reputational damage, financial loss and identity theft. You assess it on two factors: how sensitive the information was, and how likely it is to be misused. Separately, you must keep a record of every breach for 24 months, including those you decide not to report.
Can I store Canadian customer data in the United States?
Yes. PIPEDA does not prohibit cross-border transfer, but the transfer is a use and you remain accountable for the information. You must protect it through contractual or other means, and you should tell people in your privacy policy that their data may be processed outside Canada and could be accessible to foreign courts and law enforcement. Quebec is stricter: Law 25 requires a privacy impact assessment before communicating personal information outside the province.
What is the difference between PIPEDA and CASL?
PIPEDA governs how you handle personal information. CASL governs commercial electronic messages - email, SMS and similar. They overlap because you need consent under both, but CASL has its own consent rules, its own identification and unsubscribe requirements, and unlike PIPEDA it is enforced by the CRTC with administrative monetary penalties that get collected. If you send marketing email in Canada, CASL is the more immediate financial risk.
Is a privacy policy generator good enough?
It gets you a document, which is better than nothing, and it will not get you a compliant one. Generators produce policies describing generic practices rather than yours, usually anchored to US law, and a policy claiming safeguards you do not have is worse than a short accurate one. Use the template in this guide as a structure, then make each clause true. The work is in the deciding, not the drafting.
Sources
Every load-bearing claim above traces to one of these. They are primary sources - the statute, the regulator, the legislature - rather than other people's summaries, so you can check anything here rather than take our word for it.
Our audit reads your page server-side and reports which tracking scripts load, whether a consent tool is actually gating them, and which policies are linked. It measures rather than guesses, and it is free.