By the SureSend Team · Published December 29, 2025 · Updated September 2026


A client asks what you do with their information. A new vendor wants a copy of your customer list. An employee emails a spreadsheet of names and SINs to the wrong person. Each of these moments is governed by the same federal law.
This guide explains what PIPEDA is, what the name stands for, who it applies to, its 10 fair information principles, the breach rules, how it compares with HIPAA, and a practical PIPEDA compliance checklist for Canadian businesses.
Quick Summary
- It is Canada’s federal privacy law for private-sector organizations that handle personal information in commercial activity.
- It is built on 10 fair information principles, from accountability and consent to safeguards and individual access.
- Alberta, British Columbia, and Quebec have their own substantially similar private-sector laws, but the federal law still covers cross-border data flows.
- Breaches that pose a real risk of significant harm must be reported to the Privacy Commissioner and the people affected, and all breaches must be recorded for two years.
- Canada has no single HIPAA equivalent: the federal law works alongside provincial health privacy laws such as Ontario’s PHIPA.
In This Guide
- What Is PIPEDA?
- What Does PIPEDA Stand For?
- Who Does PIPEDA Apply To?
- What Counts as Personal Information?
- What Are the 10 Fair Information Principles of PIPEDA?
- What Does Consent Mean Under PIPEDA?
- What Are PIPEDA’s Breach Reporting Rules?
- Is PIPEDA Canada’s HIPAA?
- What Should a PIPEDA Compliance Checklist Include?
- What Happened to Bill C-27?
- How Does Secure File Transfer Support PIPEDA Safeguards?
- Frequently Asked Questions
- Sources
- The Bottom Line
What Is PIPEDA?
PIPEDA is Canada’s federal private-sector privacy law. It sets the ground rules for how businesses collect, use, and disclose personal information in the course of commercial activity, and it gives individuals the right to see and correct the information held about them. It received Royal Assent in 2000 and came into force in stages, applying fully to commercial activity by 2004.
The Act is overseen by the Office of the Privacy Commissioner of Canada (OPC), which investigates complaints, publishes guidance, and can take matters to the Federal Court.
What Does PIPEDA Stand For?
PIPEDA stands for the Personal Information Protection and Electronic Documents Act. The first part of the Act covers privacy; the later parts deal with electronic documents and signatures, which is why “electronic documents” appears in the name.
Who Does PIPEDA Apply To?
The Act applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity. That includes most small businesses. It also applies to:
- Federally regulated businesses, such as banks, airlines, telecommunications, and interprovincial transport, including their employee information
- Personal information that crosses provincial or national borders in the course of commercial activity
- Organizations in the territories
Alberta, British Columbia, and Quebec have private-sector privacy laws that are considered substantially similar, so they generally apply instead of the federal Act within those provinces. Several provinces also have health privacy laws, such as PHIPA in Ontario, that cover health information custodians.
What the Act does not cover
- Federal government institutions, which are covered by the Privacy Act
- Personal information collected purely for personal or domestic purposes
- Information collected only for journalistic, artistic, or literary purposes
- Business contact information used to communicate with someone about their job
What Counts as Personal Information?
Personal information is any information about an identifiable individual. Common examples include:
- Names, home addresses, phone numbers, and personal email addresses
- Social Insurance Numbers and other identification numbers
- Financial, banking, and credit information
- Medical and health information
- Employment records and evaluations
- Opinions about an individual, including reviews and disciplinary notes
What Are the 10 Fair Information Principles of PIPEDA?
PIPEDA’s ten principles are accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.


1. Accountability
Your organization is responsible for the personal information it controls and must name someone accountable for compliance.
2. Identifying Purposes
Explain why you are collecting personal information at or before the time you collect it.
3. Consent
Get meaningful consent to collect, use, or disclose personal information, except where the law allows otherwise.
4. Limiting Collection
Collect only what you need for the purposes you have identified, and do it fairly and lawfully.
5. Limiting Use, Disclosure, and Retention
Use personal information only for the purposes you collected it for, and keep it only as long as necessary.
6. Accuracy
Keep personal information as accurate, complete, and up to date as its purpose requires.
7. Safeguards
Protect personal information with security safeguards appropriate to its sensitivity, including physical, organizational, and technological measures such as encryption.
8. Openness
Make your privacy policies and practices easy to find and understand.
9. Individual Access
On request, tell people what personal information you hold about them and let them challenge its accuracy.
10. Challenging Compliance
Give people a way to raise concerns about your compliance with the person accountable for privacy.
What Does Consent Mean Under PIPEDA?
Consent is only valid if people understand what they are agreeing to. The OPC’s guidance on meaningful consent expects businesses to explain, in plain language, what information they collect, why, who it is shared with, and what the risks are. Express consent is generally expected for sensitive information such as health or financial data; implied consent may be acceptable for less sensitive information when people would reasonably expect the use.
What Are PIPEDA’s Breach Reporting Rules?
Organizations must report breaches that pose a real risk of significant harm to the Privacy Commissioner, notify the people affected, and keep records of all breaches of security safeguards for two years.
Organizations must:
- Report to the Privacy Commissioner any breach of security safeguards involving personal information that poses a real risk of significant harm to individuals
- Notify affected individuals about those breaches, and any organizations that could reduce the harm
- Keep records of all breaches of security safeguards for two years, even those that do not need to be reported
Knowingly failing to meet these reporting, notification, and record-keeping requirements is an offence that can lead to fines. Payroll and HR teams see this most often with misdirected documents; our guide on how to safely send T4 slips walks through a real example.
Is PIPEDA Canada’s HIPAA?
Not exactly. The United States regulates health information through HIPAA, a single federal law. Canada has no single equivalent: PIPEDA covers personal information in commercial activity, including health information handled by private businesses, while provinces such as Ontario regulate health information custodians through their own laws, like PHIPA.
| PIPEDA (Canada) | PHIPA (Ontario) | HIPAA (United States) | |
|---|---|---|---|
| Scope | Private-sector commercial activity | Ontario health information custodians | US health plans, providers, clearing houses, and business associates |
| Type of information | All personal information | Personal health information | Protected health information |
| Regulator | Privacy Commissioner of Canada | Information and Privacy Commissioner of Ontario | HHS Office for Civil Rights |
| Breach reporting | When there is a real risk of significant harm | To patients and, above thresholds, the IPC | To individuals and HHS |
What Should a PIPEDA Compliance Checklist Include?
Name a privacy officer, map the personal information you hold, publish a privacy policy, review consent, limit retention, protect data with encryption and secure file sharing, and prepare a breach response plan.
- Name a privacy officer who is accountable for privacy compliance.
- Map what personal information you collect, where it is stored, and who can access it.
- Publish a clear, plain-language privacy policy.
- Review how you obtain consent, especially for sensitive information.
- Limit collection and set retention periods, then securely dispose of what you no longer need.
- Protect personal information with encryption, access controls, and secure ways to share files.
- Prepare a breach response plan and a breach record log.
- Set up a process to answer access and correction requests.
- Train staff, and review contracts with vendors who handle personal information for you.
For the everyday habits behind this checklist, see our guide to document confidentiality.
What Happened to Bill C-27?
Bill C-27 proposed to replace PIPEDA’s privacy rules with a new Consumer Privacy Protection Act. The bill died when Parliament was prorogued in January 2025, so the current Act remains in force. Future reform is likely, but for now, PIPEDA compliance is what counts.
How Does Secure File Transfer Support PIPEDA Safeguards?
The safeguards principle is where file sharing matters most. Emailing personal information as a plain attachment gives you no control once it is sent. This is where SureSend comes into the picture. SureSend is a Canadian secure file transfer service that sends files through a passphrase-protected link that expires on a date you choose. SureSend uses server-side encryption: files are protected with TLS in transit and AES-256 encryption at rest, with encryption keys managed by SureSend. Here is exactly how it works:
- Create a transfer. Sign in, add one or more recipient email addresses, upload your files, and choose an expiry date of up to 21 days.
- Set a passphrase. SureSend emails each recipient a secure link, but the passphrase is never included in that email. You share it separately, by phone or text.
- The recipient downloads. They open the link, enter the passphrase, and download the files. They do not need a SureSend account.
- Track and control it. Your dashboard shows when the transfer is retrieved. You can cancel it before it is downloaded, and it expires automatically.
After you send, SureSend reminds you to share the passphrase separately, and your dashboard shows when each transfer is retrieved.
PIPEDA-Ready File Sharing
SureSend uses server-side encryption: TLS in transit and AES-256 encryption at rest, with keys managed by SureSend. Send up to 2 GB per transfer, protect it with a passphrase you share separately, set an expiry of up to 21 days, and see when it is retrieved. Your recipient needs no account. New subscribers get 30 days of Pro free, with no credit card required. Start sending securely for free.
Frequently Asked Questions
What does PIPEDA stand for?
The Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law.
Is PIPEDA federal or provincial?
Federal. Alberta, British Columbia, and Quebec have substantially similar provincial laws that generally apply within those provinces, but the federal Act still applies to federally regulated businesses and to personal information that crosses borders.
Does PIPEDA apply to small businesses?
Yes. It applies to private-sector organizations of any size that handle personal information in commercial activity, unless a substantially similar provincial law applies instead.
What information does PIPEDA not cover?
It does not cover federal government institutions, information collected purely for personal or domestic purposes, information collected only for journalistic, artistic, or literary purposes, or business contact information used to contact someone about their job.
Who enforces PIPEDA?
The Office of the Privacy Commissioner of Canada investigates complaints and can take matters to the Federal Court. Knowingly breaking the breach reporting rules is an offence that can lead to fines.
Is there a PIPEDA certification?
No. There is no official certification. Compliance is shown through your policies, practices, and records.
Sources
This article draws on the following sources.
- Office of the Privacy Commissioner of Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA). priv.gc.ca
- Office of the Privacy Commissioner of Canada. PIPEDA requirements in brief. priv.gc.ca
- Office of the Privacy Commissioner of Canada. PIPEDA fair information principles. priv.gc.ca
- Office of the Privacy Commissioner of Canada. What you need to know about mandatory reporting of breaches of security safeguards. priv.gc.ca
- Government of Canada. Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5). laws-lois.justice.gc.ca
The Bottom Line
The Act asks Canadian businesses to be accountable for personal information: collect what you need, explain why, keep it safe, and own up when something goes wrong. The safeguards principle is where most day-to-day risk sits.
Protect the information. Then send it the right way.

