Canada's Privacy Law Landscape: PIPEDA, Bill C-27, and Québec Law 25
Canada's private sector privacy framework is undergoing the most significant transformation since PIPEDA came into force in 2001. Three layers of law are relevant to most organisations handling Canadian personal data:
- PIPEDA (Personal Information Protection and Electronic Documents Act): The current federal private sector privacy law. Applies to organisations collecting, using, or disclosing personal information in the course of commercial activity, including foreign organisations doing business with Canadians.
- Québec Law 25 (Act respecting the protection of personal information in the private sector): Substantially reformed by Bill 64, now the most advanced provincial privacy law in Canada — phased in from September 2022 to September 2023, with requirements that in several respects exceed GDPR.
- Bill C-27 (Consumer Privacy Protection Act + Artificial Intelligence and Data Act): Parliament's proposal to replace PIPEDA with a modernised framework, introducing new rights, a legitimate interests basis, administrative monetary penalties up to CAD $25M or 5% of global revenues, and Canada's first federal AI regulation (ATIDA). Currently at committee stage.
Additionally, Alberta and British Columbia have provincially substantially similar legislation (PIPA AB and PIPA BC) that applies to intra-provincial private sector activity in those provinces instead of PIPEDA.
PIPEDA: 10 Fair Information Principles
PIPEDA is structured around 10 Fair Information Principles originally developed by the Canadian Standards Association. Every Canadian organisation subject to PIPEDA must implement all ten:
- Accountability: An organisation is responsible for personal information under its control and shall designate an individual (Privacy Officer or Chief Privacy Officer) accountable for compliance.
- Identifying purposes: Purposes for which personal information is collected shall be identified before or at the time of collection.
- Consent: The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.
- Limiting collection: Personal information shall be collected only to the extent necessary for the identified purposes (data minimisation).
- Limiting use, disclosure, and retention: Personal information shall not be used or disclosed for purposes other than those for which it was collected, and shall be retained only as long as necessary.
- Accuracy: Personal information shall be as accurate, complete, and up-to-date as necessary for the purposes for which it is to be used.
- Safeguards: Personal information shall be protected by security safeguards appropriate to the sensitivity of the information.
- Openness: An organisation's policies and practices relating to the management of personal information shall be readily available to individuals.
- Individual access: Upon request, an individual shall be informed of the existence, use, and disclosure of his or her personal information and shall be given access to that information.
- Challenging compliance: An individual shall be able to address a challenge concerning compliance with the above principles to the designated individual accountable for the organisation's compliance.
Consent Under PIPEDA
Consent is the cornerstone of PIPEDA. The form of consent required depends on the sensitivity of the information and the reasonable expectations of the individual:
- Express consent: Required for sensitive information — health and medical data, financial information, Social Insurance Numbers, racial/ethnic origin, religious beliefs, political opinions, sexual orientation, and biometric data. Must be clearly obtained through a positive action.
- Implied consent: Acceptable for non-sensitive information where the individual's consent can be reasonably implied from the context. Implied consent cannot be used where the individual would not reasonably expect the use or disclosure.
- Withdrawal: Individuals can withdraw consent at any time, subject to legal or contractual restrictions. The organisation must honour the withdrawal promptly and communicate the implications.
- Not a condition of service: An organisation cannot require consent to collection, use, or disclosure of personal information beyond what is necessary to provide the product or service as a condition of that service.
PIPEDA Mandatory Breach Notification (2018)
The 2015 Digital Privacy Act amendments and the Breach of Security Safeguards Regulations (SOR/2018-64) introduced mandatory breach notification obligations for PIPEDA-covered organisations:
Real Risk of Significant Harm (RROSH) Standard
An organisation must report a breach to the OPC and notify affected individuals when the breach poses a real risk of significant harm to individuals. Significant harm includes: bodily harm; humiliation; damage to reputation or relationships; loss of employment, business, or professional opportunities; financial loss; identity theft; negative effects on credit; damage to or loss of property. Factors for the RROSH determination include: the sensitivity of the personal information; the probability that it has been/is being/will be misused; the number of individuals affected; whether the information is combined with other information that increases the risk.
Notification Requirements
- OPC notification: As soon as feasible after the organisation determines a RROSH breach has occurred. No fixed statutory timeline but OPC guidance strongly recommends 72 hours as best practice. Notification must include: name/contact, circumstances of breach, date or estimated date, information involved, number of individuals affected, steps taken or to be taken to address the breach, steps taken or to be taken to notify individuals, other organisations notified.
- Individual notification: As soon as feasible for RROSH breaches; must be direct (mail, email, phone) unless it would cause further harm, in which case public communication or indirect notification may be used; must include: description, date/estimated date, information involved, steps taken, steps individuals can take to protect themselves, complaint procedure, contact information.
- 24-month breach records: ALL breaches — regardless of whether they meet the RROSH threshold — must be documented and retained for 24 months. OPC may request to inspect these records.
Individual Rights Under PIPEDA
PIPEDA Principle 9 gives individuals the right to access their personal information and to know how it has been used and disclosed:
- Access: Response required within 30 days; fees permissible only at cost recovery; limited exceptions (prohibitively costly, third-party privacy impacts, privilege, ongoing investigation, national security).
- Correction: Inaccurate information must be amended or a notation of the challenge attached if correction is refused; third parties who received the inaccurate information must be notified.
- Complaint to OPC: Individuals can file complaints with the OPC if they believe an organisation has failed to meet its PIPEDA obligations.
Québec Law 25: The Most Advanced Provincial Privacy Law in Canada
Québec's reform of private sector privacy law (Bill 64, now Law 25 / Act 25) introduced obligations that in some respects go further than GDPR:
Privacy Governance Officer (Art. 3.1)
Every private enterprise collecting, holding, using, or disclosing personal information in the course of carrying on an enterprise must designate a person in charge of the protection of personal information (responsable de la protection des renseignements personnels). The identity and contact information of this person must be published on the organisation's website.
Privacy by Default (Art. 9)
When the purpose of collecting, using, or communicating personal information can be achieved with the least amount of information, that information is the only kind an enterprise may collect. Default settings must be the most privacy-protective available.
Mandatory PIA for Technology Projects (Art. 63.5)
Before implementing any personal information technology project, enterprises must conduct a Privacy Impact Assessment (PIA). The PIA must be documented in writing and presented to the governance officer before the project is put into operation. This is broader than GDPR's DPIA trigger (which requires only high-risk processing) — in Québec, ANY personal information technology project requires a PIA.
Breach Notification (Art. 3.6 Confidentiality Incident)
A confidentiality incident means any access to, use of, or communication of personal information not authorised by law, as well as the loss of, or any other breach of, the protection of such information. Organisations must:
- Notify the Commission d'accès à l'information (CAI) of any confidentiality incident involving personal information presenting a serious risk of injury to the persons concerned — best practice is 72 hours.
- Notify affected individuals of incidents presenting a serious risk of injury.
- Maintain a confidentiality incident register for 5 years.
Right to Data Portability (Art. 27)
Individuals can request that personal information collected by the enterprise be communicated to them in a structured, commonly used, technological format — or communicated directly to another enterprise if technically feasible.
Right to De-indexing (Art. 28.1)
Where personal information was collected when the person was a minor, or its dissemination was not authorised by law — the person may request that hyperlinks providing access to that information be de-indexed. Enterprises must respond within 30 days.
Biometric Database Declaration (Art. 44)
Any enterprise that creates a biometric database must declare it to the CAI before the database is put into operation. This applies to facial recognition, fingerprint databases, voice biometrics, and similar systems.
Québec Law 25 Penalties
The CAI can impose administrative penalties:
- Up to CAD $25 million or 4% of worldwide turnover (whichever is greater) for the most serious violations.
- Up to CAD $10 million or 2% of worldwide turnover for other violations.
Bill C-27: The Consumer Privacy Protection Act (CPPA) and Artificial Intelligence and Data Act (ATIDA)
Bill C-27, introduced in June 2022, proposes three new laws to replace PIPEDA and introduce federal AI regulation:
CPPA Key Changes
- Legitimate interests basis (Art. 18): A new lawful basis for processing without consent — must satisfy a three-part test: legitimate purpose, necessity, and not overridden by individual interests/rights/freedoms. Privacy notice must disclose legitimate interests processing.
- Children's privacy (Art. 44): Verifiable parental consent required for children under 14; no targeted advertising or profiling of children.
- Right to erasure (Art. 55): Right to erasure of personal information collected when the individual was a minor for non-necessary purposes.
- Right to portability (Art. 56): Personal information portability in common electronic format on request; transfer to another organisation where technically feasible.
- Right to explanation for automated decisions (Art. 63): Individuals can request an explanation of any prediction, recommendation, or decision made solely by automated means with significant impacts; human review option must be available.
- Penalty regime: Administrative monetary penalties up to CAD $25M or 5% of global gross revenues for serious violations; CAD $10M or 3% for other violations. New Privacy Tribunal as specialist appeal body. Criminal penalties for reckless re-identification.
ATIDA (Artificial Intelligence and Data Act)
ATIDA introduces Canada's first federal AI-specific regulation:
- Applies to organisations involved in the design, development, deployment, or use of AI systems in the course of international or interprovincial trade and commerce.
- High-impact AI systems (significant impacts on employment, essential services, or criminal justice) require: impact assessments; bias mitigation; explainability documentation; monitoring; designated compliance officers.
- Prohibited AI practices: reckless use of AI systems likely to cause serious harm; use of unlawfully obtained personal information in AI systems.
- Significant penalties: up to CAD $25M or 5% of global revenues for high-impact system violations.
Assess Your Canada Privacy Compliance
Use the Canada PIPEDA / Bill C-27 Compliance Checklist to assess your organisation across 42 key controls covering current PIPEDA obligations, Québec Law 25 requirements, and forward-looking Bill C-27 CPPA/ATIDA readiness. Generate a tailored AI compliance report covering OPC and CAI enforcement risk, breach notification obligations, consent architecture gaps, and a 90-day remediation roadmap.