WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Canada Privacy & Data Protection Laws

Every regime below can apply to a business handling Canada residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 1, 2001 (phased in fully by January 1, 2004)
Personal Information Protection and Electronic Documents Act
PIPEDA

PIPEDA does not use a GDPR-style established-presence/offering/monitoring test — flagged explicitly since forcing it into that shape would misstate the law. Section 4 applies it to organizations handling personal information 'in the course of commercial activities' (plus employee data of federally-regulated businesses). Its extraterritorial reach comes from case law: courts apply a 'real and substantial connection' test (Lawson v. Accusearch, 2007 FC 125) — factors include the location of the target audience, content source, and organization. Exemptions: government institutions covered by the federal Privacy Act, personal/domestic use, journalistic/artistic/literary purposes, and business contact information. Organizations operating wholly within Alberta, British Columbia, or Quebec — which have their own 'substantially similar' private-sector laws (Quebec's Law 25 is notably stricter, with opt-in consent for tracking, a private right of action, data portability since September 2024, and penalties up to C$25M or 4% of global turnover) — are exempt from PIPEDA for information handled entirely within that province, though PIPEDA still applies to interprovincial/international flows. Reform note: PIPEDA remains the operative federal law. Bill C-27 (which would have replaced Part 1 with the Consumer Privacy Protection Act) died on the Order Paper when Parliament was prorogued in January 2025; a successor bill has since been tabled — see the pending entry below.

S.C. 2000, c. 5, Part 1, ss. 3-4Read regulation →

Sector-Specific Law · 1

July 1, 2014 (computer program installation provisions from January 15, 2015)
An Act to promote the efficiency and adaptability of the Canadian economy (Canada's Anti-Spam Legislation)
CASL

Widely described as the strictest anti-spam regime in the world, and it is a genuinely separate exposure from PIPEDA. CASL prohibits sending a commercial electronic message to an electronic address without the recipient's consent, and the default is EXPRESS consent — a positive act by the recipient — with implied consent available only in defined circumstances such as an existing business relationship, each with its own expiry. Every message must also identify the sender and carry a working unsubscribe mechanism honoured within ten business days. CASL separately prohibits installing a computer program on another person's device without consent, and altering transmission data. The CRTC can impose administrative monetary penalties of up to CAD 1 million per violation for an individual and CAD 10 million for an organization. A US-style opt-out email program lawful under CAN-SPAM is not lawful in Canada, which is the single most common compliance failure here.

S.C. 2010, c. 23Read regulation →

Cross-Border Data Transfer · 1

January 1, 2001 (Schedule 1); OPC cross-border guidelines from January 2009
Personal Information Protection and Electronic Documents Act — accountability for personal information transferred for processing
PIPEDA Principle 4.1.3

Canada does not restrict where personal information may go. PIPEDA uses an accountability model: Principle 4.1.3 makes an organization responsible for personal information in its possession or custody INCLUDING information transferred to a third party for processing, and requires contractual or other means to provide a comparable level of protection while the third party processes it. The doctrinal point that shapes everything downstream is the OPC's position that a transfer for processing is a USE of the information, not a disclosure — so no separate consent is required for the transfer itself, provided the processing serves the purpose the data was collected for. What the OPC does require is transparency: individuals should be told their information may be processed in another country and may be accessible to that country's courts and law enforcement. The OPC reopened this question after Equifax in 2019 and then reaffirmed the transfer-for-processing position. One scoping caveat: PIPEDA is displaced by substantially similar provincial private-sector laws for intra-provincial activity in Alberta, British Columbia and Quebec, and those can impose stricter transfer requirements — confirm which regime actually governs before relying on this entry.

PIPEDA, S.C. 2000, c. 5, Schedule 1, Principle 4.1.3 (Accountability); OPC Guidelines for processing personal data across borders (2009)Read regulation →

Data Security & Breach Notification · 1

The trigger is a 'real risk of significant harm' to an individual — a materially different test from the GDPR's, and one PIPEDA defines expansively enough to catch humiliation, damage to reputation or relationships, and loss of employment or business opportunity, not just financial loss and identity theft. Where it is met, the organization must report to the Office of the Privacy Commissioner as soon as feasible, notify affected individuals, and notify any other organization that may be able to reduce the risk. The duty most often missed is the one that has no threshold at all: s. 10.3 requires keeping a record of EVERY breach of security safeguards, reportable or not, for 24 months, and the OPC can demand those records. Applies to breaches involving personal information under an organization's control in the course of commercial activity, including where the processing itself happened outside Canada.

PIPEDA, S.C. 2000, c. 5, ss. 10.1-10.3; Breach of Security Safeguards Regulations, SOR/2018-64Read regulation →

On the Horizon — Proposed, Not Yet Law · 1

Canada
Bill C-36, the Protecting Privacy and Consumer Data Act

If enacted, C-36 would enact the Protecting Privacy and Consumer Data Act, repeal Part 1 of PIPEDA, rename the remainder the Electronic Documents Act, and replace the private-sector privacy regime with a standalone statute. Three differences from the failed C-27 matter for planning. AI regulation has been decoupled entirely (the Artificial Intelligence and Data Act is not carried forward, leaving Canada without a comprehensive federal AI statute). The bill frames privacy as a fundamental right rather than as a balance against commercial interests — a framing that shapes how its consent, de-identification, and enforcement provisions are read. And it is institutionally disruptive in a way C-27 was not: it would establish a Digital Safety and Data Protection Commission of Canada as the federal private-sector privacy regulator in place of the Office of the Privacy Commissioner, so an organization's Canadian supervisory counterparty would change, not just its obligations. Expect administrative monetary penalties well above PIPEDA's current (effectively nonexistent) fine exposure if it passes. Because the bill is live legislation, treat every specific in it as subject to amendment.

Status: Not law, and it has not moved since introduction. Canada's federal private-sector privacy reform has now failed once already: Bill C-27, which bundled the Consumer Privacy Protection Act, a Data Protection Tribunal Act, and the Artificial Intelligence and Data Act, died on the Order Paper when Parliament was prorogued January 6, 2025. Its successor, Bill C-36, was sponsored by the Minister of Artificial Intelligence and Digital Innovation and received first reading in the House of Commons on June 15, 2026. LEGISinfo records it as at second reading in the House of Commons with no activity yet recorded at that stage; the House's fall sittings resume September 21, 2026. PIPEDA remains the operative federal law until and unless the bill passes.

Other Americas jurisdictions