Data & Privacy ยท Canada
Data protection & privacy law in Canada (2026)
Canada shaded by its data & privacy status
Data protection in Canada: comprehensive law.
FrameworkPersonal Information Protection and Electronic Documents Act (PIPEDA), 2000 (federal private sector), and the Privacy Act, 1985 (federal public sector), supervised by the Office of the Privacy Commissioner of Canada (OPC); substantially similar provincial regimes include Quebec's Law 25, Alberta PIPA and British Columbia PIPA.
Canada has a mature, comprehensive federal private-sector data-protection law โ PIPEDA โ in force since 2001 (fully applicable from 2004), overseen by the Office of the Privacy Commissioner of Canada, complemented by the federal Privacy Act for government institutions and by substantially-similar provincial laws in Quebec, Alberta and British Columbia. A GDPR-style modernization package (Bill C-27, containing the Consumer Privacy Protection Act, the Tribunal Act and the AIDA) died on the Order Paper when Parliament was prorogued in January 2025 and has not been reintroduced as of mid-2026, though the federal budget signaled a new private-sector privacy statute and tribunal bill are being prepared. Meanwhile, Quebec's Law 25 (fully in force since September 2024) currently sets the strictest bar in the country, with GDPR-like consent, breach and PIA obligations and administrative penalties up to CA$25M or 4% of worldwide turnover.
Key points
PIPEDA applies to organizations that collect, use or disclose personal information in the course of commercial activities across Canada, based on 10 Fair Information Principles (Schedule 1) grounded in consent, purpose limitation, accuracy, safeguards and accountability. It applies federally except where a province has enacted 'substantially similar' private-sector legislation (Quebec, Alberta, BC).
The Office of the Privacy Commissioner of Canada (OPC) is the independent federal regulator that investigates complaints, conducts audits, publishes guidance and pursues enforcement under both PIPEDA and the Privacy Act; it works jointly with provincial commissioners (e.g., a 2026 joint investigation of OpenAI OpCo, LLC was published on 6 May 2026).
Since 1 November 2018, organizations subject to PIPEDA must report to the OPC and notify affected individuals of any breach of security safeguards that creates a 'real risk of significant harm' (RROSH), regardless of the number of people affected, and must keep records of ALL breaches for 24 months.
Bill C-27 โ which would have replaced PIPEDA's private-sector provisions with the Consumer Privacy Protection Act (CPPA), created a Personal Information and Data Protection Tribunal with penalty powers up to 5% of global revenue, and enacted the Artificial Intelligence and Data Act (AIDA) โ died on the Order Paper when Parliament was prorogued in January 2025 and had not been reintroduced by mid-2026, though the government has signaled a new private-sector privacy bill is planned.
Quebec's Act respecting the protection of personal information in the private sector, as modernized by Law 25, has been fully in force since 22 September 2024 and imposes GDPR-style obligations โ designated privacy officer, mandatory PIAs, granular consent, cross-border transfer assessments, portability, and administrative monetary penalties up to CA$25M or 4% of worldwide turnover โ enforced by the Commission d'accรจs ร l'information (CAI). Alberta and BC each have their own PIPA statutes.
The federal Privacy Act (R.S.C. 1985, c. P-21) governs the handling of personal information by federal government institutions and is also enforced by the OPC. Separately, Bill C-8 (Critical Cyber Systems Protection Act) received Royal Assent on 15 June 2026, imposing mandatory cybersecurity programs and incident-reporting duties on operators of designated critical cyber systems in federally regulated sectors โ complementing but not replacing PIPEDA.
Timeline - major decisions & events
A joint investigation by the federal OPC and the Quebec, BC, and Alberta authorities found TikTok collected sensitive data, including biometric and profiling data, from hundreds of thousands of Canadian children; TikTok agreed to strengthen age assurance and stop targeting users under 18.
Office of the Privacy Commissioner of Canada โWhen Parliament was prorogued, Bill C-27 (the Digital Charter Implementation Act, 2022) died on the Order Paper, killing the proposed Consumer Privacy Protection Act and Artificial Intelligence and Data Act; Canada remains governed by the 2000-era PIPEDA.
LEGISinfo, Parliament of Canada โIn Canada (Privacy Commissioner) v. Facebook, 2024 FCA 140, the court overturned a lower ruling and found Facebook failed to obtain meaningful consent and to safeguard data in the Cambridge Analytica matter, clarifying the 'reasonable consumer' standard for consent.
Office of the Privacy Commissioner of Canada โIn its first review since 2001, the European Commission concluded PIPEDA continues to provide protection 'essentially equivalent' to the EU, preserving unrestricted EU-to-Canada data flows for organizations subject to PIPEDA.
European Commission โA joint federal-provincial investigation found the Tim Hortons app tracked users' location every few minutes, even when closed, without meaningful consent, collecting 'vast amounts' of sensitive data via a US provider, Radar.
Office of the Privacy Commissioner of Canada โQuebec became the first Canadian jurisdiction to substantially modernize its privacy regime, adding breach notification, consent, data portability, and significant penalties; provisions phased in through 2022-2024, raising the bar nationally.
National Assembly of Quรฉbec โA joint federal-provincial investigation concluded Clearview AI's scraping of billions of facial images from the internet was unlawful mass surveillance violating PIPEDA; commissioners ordered it to stop collecting and to delete images of Canadians.
Office of the Privacy Commissioner of Canada โOrganizations became legally required to report breaches posing a 'real risk of significant harm' to the Privacy Commissioner, notify affected individuals, and keep breach records, Canada's first nationwide mandatory breach regime for the private sector.
Canada Gazette โThis amendment to PIPEDA introduced mandatory breach reporting and recordkeeping obligations and strengthened consent requirements, laying the groundwork for the breach rules that took effect in 2018.
Justice Laws Website, Government of Canada โThe Commission ruled that PIPEDA provided adequate protection under the EU Data Protection Directive, enabling cross-border EU-to-Canada data transfers, a key external driver for Canada's privacy framework.
EUR-Lex, European Union โCanada - other topics
Data & Privacy in other countries
Last verified 8/17/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ