Privacy laws · Canada

Personal Information Protection and Electronic Documents Act.

Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information in the course of commercial activity. Based on 10 fair information principles. Applies to businesses that collect personal information from Canadian residents.

/ Diagnostic check ClearConsent scans your storefront for signals related to this law — consent banner state, GPC support, Do Not Sell links, privacy policy disclosures, cookies, and trackers.

/ Effective
2000-01-01
Effective date
When the law took effect or will take effect.
/ Consumers
None
Consumer threshold
The number of Canada residents whose data triggers compliance.
/ Revenue
None
Revenue threshold
Annual revenue trigger for compliance, if applicable.
01 / Key requirements

What the law requires.

  • 01Accountability: designate individual responsible for compliance
  • 02Identifying purposes: document why data is collected before or at time of collection
  • 03Meaningful consent: obtain knowledge and consent for collection, use, and disclosure
  • 04Limiting collection: collect only what is necessary for identified purposes
  • 05Limiting use, disclosure, and retention: use data only for stated purposes
  • 06Accuracy: keep personal information accurate, complete, and up-to-date
  • 07Safeguards: protect personal information with appropriate security
  • 08Openness: make privacy policies readily available
  • 09Individual access: right to access and challenge accuracy of personal information
  • 10Challenging compliance: provide mechanism to address complaints
  • 11Mandatory breach reporting to OPC and affected individuals
02 / Enforcement

Penalties & cure period.

Penalties

OPC can seek Federal Court orders. Non-compliance with orders can result in fines up to $100,000 CAD per violation. Individuals can sue for damages.

Cure period

OPC investigates complaints and typically recommends remediation before enforcement

Enforcement agency

Office of the Privacy Commissioner of Canada (OPC)

03 / E-commerce

What this means for
your store.

Applies to any business collecting personal information from Canadian customers. Consent requirements are less strict than GDPR but stricter than most US state laws. Quebec has its own provincial law (Law 25) with GDPR-like requirements.

Scan your store for PIPEDA privacy gaps →