Cross-Border Data Transfer
Personal Information Protection and Electronic Documents Act — accountability for personal information transferred for processing
Canada · January 1, 2001 (Schedule 1); OPC cross-border guidelines from January 2009
Canada does not restrict where personal information may go. PIPEDA uses an accountability model: Principle 4.1.3 makes an organization responsible for personal information in its possession or custody INCLUDING information transferred to a third party for processing, and requires contractual or other means to provide a comparable level of protection while the third party processes it. The doctrinal point that shapes everything downstream is the OPC's position that a transfer for processing is a USE of the information, not a disclosure — so no separate consent is required for the transfer itself, provided the processing serves the purpose the data was collected for. What the OPC does require is transparency: individuals should be told their information may be processed in another country and may be accessible to that country's courts and law enforcement. The OPC reopened this question after Equifax in 2019 and then reaffirmed the transfer-for-processing position. One scoping caveat: PIPEDA is displaced by substantially similar provincial private-sector laws for intra-provincial activity in Alberta, British Columbia and Quebec, and those can impose stricter transfer requirements — confirm which regime actually governs before relying on this entry.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.