Which Canadian privacy law actually reaches your organization?

Most privacy confusion in Canada comes from one assumption: that there is a national privacy rule the way there is a national criminal code. There is not. There are several instruments with different triggers, and a programme built against the wrong one answers questions nobody will ask while leaving the real duty unmet.

The short version

Work out which instrument reaches you before buying any compliance programme, because the answer changes the breach obligations, the consent model and the regulator you would be dealing with. Four instruments account for most Canadian organizations, and the trigger for each is different in kind — one is about the activity, one about the province and the sector, one about being a public body, and one about a province with its own comprehensive regime.

PIPEDA: the federal private-sector Act

The Personal Information Protection and Electronic Documents Act applies to organizations that collect, use or disclose personal information in the course of commercial activity, and to federal works, undertakings and businesses — banking, telecommunications, interprovincial transport, broadcasting — including in respect of their employees.

Its breach duty is explicit. Section 10.1(1) requires an organization to report to the Commissioner any breach of security safeguards involving personal information under its control where it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual, and the Act goes on to require notification to the individual and the keeping of records of breaches.

BC PIPA: the British Columbia private sector

BC’s Personal Information Protection Act applies to organizations in the province — companies, non-profits, associations, trade unions — covering customer and employee information alike. Its Part 9 deals with the care of personal information, with protection and retention as separate duties.

The point most often got wrong is the breach position, and it is got wrong confidently and in print. We set out what the Act does and does not require, and where the mistaken claim comes from, in reporting a breach in BC. It is worth reading before acting on any deadline somebody has quoted you.

BC FIPPA: public bodies, and their suppliers

The Freedom of Information and Protection of Privacy Act governs British Columbia public bodies: ministries, health authorities, public universities and colleges, school districts, municipalities and many others. Private universities and private career colleges are generally private-sector organizations under BC PIPA instead. It combines access-to-records duties with privacy duties, and it reaches service providers directly in section 25.1, which binds an employee or associate of a service provider in the same terms as a public body’s own staff.

Section 30 requires the public body to protect personal information in its custody or under its control by making reasonable security arrangements, and section 36.3 requires notification of affected individuals and of the commissioner where a privacy breach could reasonably be expected to result in significant harm. For a supplier the practical consequence is contractual, and it is set out in what a vendor bidding into a BC public body is asked to demonstrate.

Quebec’s Law 25

Quebec has its own comprehensive private-sector regime, reformed by the statute usually referred to as Law 25. It is named here because it is a real driver of Canadian programme work: organizations with Quebec customers or employees are frequently building to it, and it is often the instrument that sets the bar for a national programme.

We assert no obligation under it on this page. Nothing about its requirements was verified against LégisQuébec or the Commission d’accès à l’information for this piece, and stating a duty we have not read would be exactly the failure this site exists to avoid. Where Quebec is in scope for an engagement, the detail is confirmed against LégisQuébec or the Commission at that point, alongside your counsel.

Substantially similar legislation

The phrase has a specific statutory home. Under section 26(2)(b) of PIPEDA the Governor in Council may, if satisfied that the legislation of a province is substantially similar to that Part and applies to an organization, a class of organizations, an activity or a class of activities, exempt that organization, activity or class from the application of the federal Part in respect of the collection, use or disclosure of personal information within the province.

Two things follow, and both matter commercially. The exemption is granted by order and operates within the province, so information crossing a provincial or national border can still engage the federal Act. And the provincial Act that replaces it is substantially similar rather than identical, which is why a programme cannot simply be copied from one jurisdiction to another.

A short decision path

If the organization is…Start from
A BC public bodyFIPPA
A supplier to a BC public bodyYour contract, which carries FIPPA duties to you
A federal work, undertaking or businessPIPEDA
A BC private-sector organization or non-profitBC PIPA, with PIPEDA for information crossing borders
Handling Quebec personal informationQuebec’s regime, confirmed with counsel
Offering services to people in the EUYour Canadian Act and the GDPR together

Yes, more than one can apply at once. A national organization routinely sits under a provincial Act for its local employment and customer records and under the federal Act for information it handles across provincial or national borders. The table is a starting point for a conversation with counsel, not a substitute for one.

What is the same across all of them

More than the differences suggest. Every instrument expects you to know what personal information you hold and why; to limit collection to what the purpose needs; to protect it with measures proportionate to its sensitivity; to keep it no longer than the purpose requires; to let individuals see what you hold about them and have it corrected; and to be accountable — a named person, written policies, and a demonstrable practice rather than an intention.

That common core is most of the programme, which is the useful news: it can be built before the jurisdictional question is fully settled, and it is what Canadian privacy readiness covers. The control-level mapping is in the statute-to-control map.

Where they actually differ in practice

  • Breach duties. The clearest and most consequential difference, and the one most often misstated in sales material.
  • Consent. What counts as valid consent, and when an exception applies, varies between the instruments.
  • Employee information. Covered in some contexts and not others, which surprises organizations that assumed a single rule.
  • Who regulates you. A federal commissioner, a provincial commissioner, or a provincial commission — with different powers and different published expectations.

Artificial intelligence sits across all of this without an instrument of its own: the federal bill that would have created one did not pass, which is the subject of what happened to AIDA.

What follows: the programme each one implies

Once the instrument is settled, the work resolves into five things, and the order rarely changes.

  1. An inventory. What personal information you hold, where it lives, who can reach it and why. Nothing else can be done accurately without it, and almost nobody has one that is current.
  2. A lawful basis and a consent position for each collection, written down in the terms the applicable instrument uses rather than in general terms.
  3. Security measures proportionate to sensitivity, and the evidence that they operate — which is where a privacy programme becomes a security programme.
  4. A retention schedule with destruction that actually happens, including in backups and exports.
  5. Individual rights and a breach process that can run on the timeline the instrument sets, rehearsed before it is needed.

Where the instruments diverge is mostly in items two and five. Items one, three and four are common ground, which is why an organization uncertain about its jurisdiction should start there rather than wait.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can more than one privacy law apply at once?

Yes, more than one can apply at once. A national organization routinely sits under a provincial Act for its local employment and customer records and under the federal Act for information it handles across provincial or national borders.

Does the location of our servers decide it?

The location of your servers does not decide which Act applies. What the organization is, where it operates and what it does with the information decide it; residency is usually a contractual requirement rather than a statutory trigger.

Where does the EU GDPR fit?

The EU General Data Protection Regulation reaches organizations outside the Union that offer goods or services to people in it or monitor their behaviour, so a Canadian company can be under a Canadian Act and the GDPR at the same time. The consolidated text is published on EUR-Lex.

Why does it matter which one applies?

Work out which instrument reaches you before buying any compliance programme, because the answer changes the breach obligations, the consent model and the regulator you would be dealing with.

Nothing here is legal advice. Which instrument reaches a particular organization is a question for its counsel; this page describes the instruments and links their official texts so the conversation starts from the same place.

Working out which one reaches you

Describe what the organization is, where it operates and whose information it holds. The reply says which instruments are in play and what the common core of the programme looks like. More of our writing is indexed at writing.

Discuss a scope