What Is PIPEDA? A Plain-Language Guide to Canada’s Privacy Law

December 29, 2025

A green shield protecting people and documents, representing PIPEDA, Canada's private-sector privacy law
PIPEDA sets the rules for how Canadian businesses handle personal information.

A client asks what you do with their information. A new vendor wants a copy of your customer list. An employee emails a spreadsheet of names and SINs to the wrong person. Each of these moments is governed by the same federal law.

This guide explains what PIPEDA is, what the name stands for, who it applies to, its 10 fair information principles, the breach rules, how it compares with HIPAA, and a practical PIPEDA compliance checklist for Canadian businesses.

Quick Summary

  • It is Canada’s federal privacy law for private-sector organizations that handle personal information in commercial activity.
  • It is built on 10 fair information principles, from accountability and consent to safeguards and individual access.
  • Alberta, British Columbia, and Quebec have their own substantially similar private-sector laws, but the federal law still covers cross-border data flows.
  • Breaches that pose a real risk of significant harm must be reported to the Privacy Commissioner and the people affected, and all breaches must be recorded for two years.
  • Canada has no single HIPAA equivalent: the federal law works alongside provincial health privacy laws such as Ontario’s PHIPA.

What Is PIPEDA?

PIPEDA is Canada’s federal private-sector privacy law. It sets the ground rules for how businesses collect, use, and disclose personal information in the course of commercial activity, and it gives individuals the right to see and correct the information held about them. It received Royal Assent in 2000 and came into force in stages, applying fully to commercial activity by 2004.

The Act is overseen by the Office of the Privacy Commissioner of Canada (OPC), which investigates complaints, publishes guidance, and can take matters to the Federal Court.

What Does PIPEDA Stand For?

PIPEDA stands for the Personal Information Protection and Electronic Documents Act. The first part of the Act covers privacy; the later parts deal with electronic documents and signatures, which is why “electronic documents” appears in the name.

Who Does PIPEDA Apply To?

The Act applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity. That includes most small businesses. It also applies to:

  • Federally regulated businesses, such as banks, airlines, telecommunications, and interprovincial transport, including their employee information
  • Personal information that crosses provincial or national borders in the course of commercial activity
  • Organizations in the territories

Alberta, British Columbia, and Quebec have private-sector privacy laws that are considered substantially similar, so they generally apply instead of the federal Act within those provinces. Several provinces also have health privacy laws, such as PHIPA in Ontario, that cover health information custodians.

What the Act does not cover

  • Federal government institutions, which are covered by the Privacy Act
  • Personal information collected purely for personal or domestic purposes
  • Information collected only for journalistic, artistic, or literary purposes
  • Business contact information used to communicate with someone about their job

What Counts as Personal Information?

Personal information is any information about an identifiable individual. Common examples include:

  • Names, home addresses, phone numbers, and personal email addresses
  • Social Insurance Numbers and other identification numbers
  • Financial, banking, and credit information
  • Medical and health information
  • Employment records and evaluations
  • Opinions about an individual, including reviews and disciplinary notes

What Are the 10 Fair Information Principles of PIPEDA?

PIPEDA’s ten principles are accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

A checklist of ten items with green checkmarks, representing the 10 fair information principles of PIPEDA
PIPEDA’s obligations flow from ten fair information principles.

1. Accountability

Your organization is responsible for the personal information it controls and must name someone accountable for compliance.

2. Identifying Purposes

Explain why you are collecting personal information at or before the time you collect it.

3. Consent

Get meaningful consent to collect, use, or disclose personal information, except where the law allows otherwise.

4. Limiting Collection

Collect only what you need for the purposes you have identified, and do it fairly and lawfully.

5. Limiting Use, Disclosure, and Retention

Use personal information only for the purposes you collected it for, and keep it only as long as necessary.

6. Accuracy

Keep personal information as accurate, complete, and up to date as its purpose requires.

7. Safeguards

Protect personal information with security safeguards appropriate to its sensitivity, including physical, organizational, and technological measures such as encryption.

8. Openness

Make your privacy policies and practices easy to find and understand.

9. Individual Access

On request, tell people what personal information you hold about them and let them challenge its accuracy.

10. Challenging Compliance

Give people a way to raise concerns about your compliance with the person accountable for privacy.

Consent is only valid if people understand what they are agreeing to. The OPC’s guidance on meaningful consent expects businesses to explain, in plain language, what information they collect, why, who it is shared with, and what the risks are. Express consent is generally expected for sensitive information such as health or financial data; implied consent may be acceptable for less sensitive information when people would reasonably expect the use.

What Are PIPEDA’s Breach Reporting Rules?

Organizations must report breaches that pose a real risk of significant harm to the Privacy Commissioner, notify the people affected, and keep records of all breaches of security safeguards for two years.

Organizations must:

  • Report to the Privacy Commissioner any breach of security safeguards involving personal information that poses a real risk of significant harm to individuals
  • Notify affected individuals about those breaches, and any organizations that could reduce the harm
  • Keep records of all breaches of security safeguards for two years, even those that do not need to be reported

Knowingly failing to meet these reporting, notification, and record-keeping requirements is an offence that can lead to fines. Payroll and HR teams see this most often with misdirected documents; our guide on how to safely send T4 slips walks through a real example.

Is PIPEDA Canada’s HIPAA?

Not exactly. The United States regulates health information through HIPAA, a single federal law. Canada has no single equivalent: PIPEDA covers personal information in commercial activity, including health information handled by private businesses, while provinces such as Ontario regulate health information custodians through their own laws, like PHIPA.

PIPEDA (Canada)PHIPA (Ontario)HIPAA (United States)
ScopePrivate-sector commercial activityOntario health information custodiansUS health plans, providers, clearing houses, and business associates
Type of informationAll personal informationPersonal health informationProtected health information
RegulatorPrivacy Commissioner of CanadaInformation and Privacy Commissioner of OntarioHHS Office for Civil Rights
Breach reportingWhen there is a real risk of significant harmTo patients and, above thresholds, the IPCTo individuals and HHS

What Should a PIPEDA Compliance Checklist Include?

Name a privacy officer, map the personal information you hold, publish a privacy policy, review consent, limit retention, protect data with encryption and secure file sharing, and prepare a breach response plan.

  1. Name a privacy officer who is accountable for privacy compliance.
  2. Map what personal information you collect, where it is stored, and who can access it.
  3. Publish a clear, plain-language privacy policy.
  4. Review how you obtain consent, especially for sensitive information.
  5. Limit collection and set retention periods, then securely dispose of what you no longer need.
  6. Protect personal information with encryption, access controls, and secure ways to share files.
  7. Prepare a breach response plan and a breach record log.
  8. Set up a process to answer access and correction requests.
  9. Train staff, and review contracts with vendors who handle personal information for you.

For the everyday habits behind this checklist, see our guide to document confidentiality.

What Happened to Bill C-27?

Bill C-27 proposed to replace PIPEDA’s privacy rules with a new Consumer Privacy Protection Act. The bill died when Parliament was prorogued in January 2025, so the current Act remains in force. Future reform is likely, but for now, PIPEDA compliance is what counts.

How Does Secure File Transfer Support PIPEDA Safeguards?

The safeguards principle is where file sharing matters most. Emailing personal information as a plain attachment gives you no control once it is sent. This is where SureSend comes into the picture. SureSend is a Canadian secure file transfer service that sends files through a passphrase-protected link that expires on a date you choose. SureSend uses server-side encryption: files are protected with TLS in transit and AES-256 encryption at rest, with encryption keys managed by SureSend. Here is exactly how it works:

  1. Create a transfer. Sign in, add one or more recipient email addresses, upload your files, and choose an expiry date of up to 21 days.
  2. Set a passphrase. SureSend emails each recipient a secure link, but the passphrase is never included in that email. You share it separately, by phone or text.
  3. The recipient downloads. They open the link, enter the passphrase, and download the files. They do not need a SureSend account.
  4. Track and control it. Your dashboard shows when the transfer is retrieved. You can cancel it before it is downloaded, and it expires automatically.

After you send, SureSend reminds you to share the passphrase separately, and your dashboard shows when each transfer is retrieved.

SureSend — Create New EdE dialog Create New EdE Fill in the details to create a new ede. EdE Name Recipient + Add Another Passphrase Passphrase for recipient Expires In 1 day 7 days 14 days 21 days September 27, 2026 Add File Drag and drop files or folders here, or click to select files. (Max file size: 2GB) Unencrypted Note Optional note to the recipient. Please do not include the passphrase here. Send EdE Cancel
Creating a transfer: add recipients, set a passphrase, choose an expiry of up to 21 days, and upload your files. Illustration with sample data.
SureSend — EdE Transfer Complete EdE Transfer Complete 1 EdE successfully sent. Don’t forget to let the recipient(s) know the passphrase.
After sending, SureSend reminds you to share the passphrase separately. Illustration with sample data.
SureSend — EdE Transfers dashboard EdE Transfers Contacts Encrypted Digital Envelopes (EdEs) Create New EdE EdE Name Recipient Files Status Date Sent Status Changed Actions Contract jane@example.com contract.pdf Retrieved 21/09/26, 09:11 GMT-4 21/09/26, 13:45 GMT-4 Photos sam@example.com photos.zip Expired 18/09/26, 15:30 GMT-4 18/09/26, 15:43 GMT-4 Export CSV 1
Your SureSend dashboard shows when each transfer is retrieved or has expired. Illustration with sample data.

PIPEDA-Ready File Sharing

SureSend uses server-side encryption: TLS in transit and AES-256 encryption at rest, with keys managed by SureSend. Send up to 2 GB per transfer, protect it with a passphrase you share separately, set an expiry of up to 21 days, and see when it is retrieved. Your recipient needs no account. New subscribers get 30 days of Pro free, with no credit card required. Start sending securely for free.

Frequently Asked Questions

What does PIPEDA stand for?

The Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law.

Is PIPEDA federal or provincial?

Federal. Alberta, British Columbia, and Quebec have substantially similar provincial laws that generally apply within those provinces, but the federal Act still applies to federally regulated businesses and to personal information that crosses borders.

Does PIPEDA apply to small businesses?

Yes. It applies to private-sector organizations of any size that handle personal information in commercial activity, unless a substantially similar provincial law applies instead.

What information does PIPEDA not cover?

It does not cover federal government institutions, information collected purely for personal or domestic purposes, information collected only for journalistic, artistic, or literary purposes, or business contact information used to contact someone about their job.

Who enforces PIPEDA?

The Office of the Privacy Commissioner of Canada investigates complaints and can take matters to the Federal Court. Knowingly breaking the breach reporting rules is an offence that can lead to fines.

Is there a PIPEDA certification?

No. There is no official certification. Compliance is shown through your policies, practices, and records.

Sources

This article draws on the following sources.

  • Office of the Privacy Commissioner of Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA). priv.gc.ca
  • Office of the Privacy Commissioner of Canada. PIPEDA requirements in brief. priv.gc.ca
  • Office of the Privacy Commissioner of Canada. PIPEDA fair information principles. priv.gc.ca
  • Office of the Privacy Commissioner of Canada. What you need to know about mandatory reporting of breaches of security safeguards. priv.gc.ca
  • Government of Canada. Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5). laws-lois.justice.gc.ca

The Bottom Line

The Act asks Canadian businesses to be accountable for personal information: collect what you need, explain why, keep it safe, and own up when something goes wrong. The safeguards principle is where most day-to-day risk sits.

Protect the information. Then send it the right way.

Related Posts