WorldPrivacyAtlasInternational Privacy & Data Protection Law Matcher

Jurisdiction Guide

Canada Privacy & Data Protection Laws

Every regime below can apply to a business handling Canada residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 1, 2001 (phased in fully by January 1, 2004)
Personal Information Protection and Electronic Documents Act
PIPEDA

PIPEDA does not use a GDPR-style established-presence/offering/monitoring test — flagged explicitly since forcing it into that shape would misstate the law. Section 4 applies it to organizations handling personal information 'in the course of commercial activities' (plus employee data of federally-regulated businesses). Its extraterritorial reach comes from case law: courts apply a 'real and substantial connection' test (Lawson v. Accusearch, 2007 FC 125) — factors include the location of the target audience, content source, and organization. Exemptions: government institutions covered by the federal Privacy Act, personal/domestic use, journalistic/artistic/literary purposes, and business contact information. Organizations operating wholly within Alberta, British Columbia, or Quebec — which have their own 'substantially similar' private-sector laws (Quebec's Law 25 is notably stricter, with opt-in consent for tracking, a private right of action, and penalties up to C$25M or 4% of global turnover) — are exempt from PIPEDA for information handled entirely within that province, though PIPEDA still applies to interprovincial/international flows.

S.C. 2000, c. 5, Part 1, ss. 3-4Read regulation →