PIPEDA: A Plain-English Guide to Canadian Privacy Law for Small Businesses

A practical guide to Canada's federal privacy law, PIPEDA, for small businesses. Who it applies to, the 10 fair information principles, access requests, breach notification, penalties, provincial laws, and the status of reform (Bill C-36).

Last updated: 2026-06-23

If you run a business in Canada that collects customer data — in 2026, that is virtually every business — you are governed by PIPEDA. Unlike the US, there is no revenue or size threshold: if you are in commercial activity and you collect personal information, the law applies. This guide explains what PIPEDA requires and where Canadian privacy reform now stands.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified lawyer or privacy professional for guidance specific to your business. The information here is based on PIPEDA (S.C. 2000, c. 5) and guidance from the Office of the Privacy Commissioner of Canada, as of the date below.

PIPEDA — the Personal Information Protection and Electronic Documents Act — is Canada's federal private-sector privacy law, regulated by the Office of the Privacy Commissioner of Canada (OPC). For a comprehensive walkthrough, see our detailed PIPEDA compliance guide.

Does This Law Apply to Your Business?

PIPEDA applies to private-sector organisations that collect, use, or disclose personal information in the course of commercial activity, and to federally regulated businesses (banks, airlines, telecommunications) regardless of province. There is no small-business exemption — a sole proprietor running an online shop is covered.

Three provinces have their own substantially similar private-sector laws that apply instead of PIPEDA for intra-provincial activity:

  • Quebec — Law 25, now fully in force and the strictest in the country;
  • Alberta — Personal Information Protection Act (PIPA);
  • British Columbia — Personal Information Protection Act (PIPA).

Unless you are certain you operate wholly within Alberta, BC, or Quebec, assume PIPEDA applies — and note that data crossing provincial or national borders brings you under PIPEDA regardless.

What Rights Do Individuals Have?

PIPEDA gives individuals rights grounded in its fair information principles:

RightBasisKey detail
AccessPrinciple 4.9Request the personal information you hold; respond within 30 days
Correction / accuracyPrinciple 4.9Challenge accuracy and have information corrected
Withdraw consentPrinciple 4.3Withdraw consent, subject to legal or contractual limits
Marketing opt-outPrinciple 4.3Opt out of secondary uses such as marketing
Complain to the OPCPIPEDA s.11Lodge a complaint with the Privacy Commissioner

PIPEDA does not currently include a GDPR-style right to erasure or data portability, and there is no private right of action — enforcement runs through the OPC. (Quebec's Law 25 goes further, with deletion and portability rights and a private right of action.)

What Your Business Must Do

PIPEDA is built on 10 fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. In practice:

  • Appoint a privacy lead accountable for compliance (in a small business, often the owner).
  • Obtain meaningful consent — clear, specific, and informed; express consent for sensitive data.
  • Collect only what you need and use it only for the identified purpose.
  • Publish a clear privacy policy (see do I need a privacy policy?).
  • Respond to access requests within 30 days.
  • Safeguard personal information with measures proportionate to its sensitivity.

A current data inventory is the foundation for both access requests and breach response.

Breach Notification

Since November 2018, PIPEDA requires mandatory reporting of a breach of security safeguards that creates a real risk of significant harm. You must report to the OPC and notify affected individuals as soon as feasible, notify any organisation that could reduce the harm, and keep records of every breach (reportable or not) for at least two years.

Penalties

Under current PIPEDA, fines are limited — up to CAD $100,000 for certain narrow offences (such as failing to keep breach records or obstructing the Commissioner). The OPC cannot levy large administrative penalties for ordinary non-compliance, though investigations, public findings, and Federal Court proceedings carry real reputational and legal weight. (Quebec's Law 25 already imposes penalties up to the greater of CAD $25 million or 4% of worldwide turnover.)

The Status of Reform: Bill C-36

Federal reform has been a long road. Bill C-27 (containing the Consumer Privacy Protection Act and the AI law AIDA) died when Parliament was prorogued in January 2025. Its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, received first reading on 15 June 2026 and is at an early stage. It is reported to carry forward much of the CPPA — substantially higher penalties (up to the greater of CAD $25 million or 5% of global revenue for the most serious offences), stronger protection for children's data, and a new right to deletion — but it does not revive AIDA, so Canada still has no comprehensive AI statute.

For now, PIPEDA remains the law in force. Build to current requirements; most of C-36 extends principles PIPEDA already contains. We track progress on the data governance news page.

References

Last reviewed: June 2026. Canadian privacy law is mid-reform. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.