Skip to Content
McCarthy Tétrault
Share This Page

Privacy Laws: Doing Business in Canada 2026


September 22, 2026Publication

This chapter is part of our Doing Business in Canada guide, designed to help global investors navigate the legal, regulatory and strategic considerations that affect investment decisions, execution, and long-term success in Canada.


Privacy Laws

All businesses in Canada are subject to legislation that regulates the collection, use, and disclosure of personal information in the course of commercial activity and in some jurisdictions, in the management of employees. “Personal information” generally means information about an identifiable individual. The collection, use, and disclosure of personal information by private sector organizations within the provinces of British Columbia, Alberta, and Québec are regulated by legislation enacted by each of those provinces, while a federal private sector privacy law governs the collection and processing of personal information in the rest of Canada.

These statutory regimes are all generally built upon the following 10 principles that govern the collection, use, and disclosure of personal information:

  • accountability;
  • identifying purposes;
  • consent;
  • limiting collection;
  • limiting use, disclosure, and retention;
  • accuracy;
  • security safeguards;
  • openness;
  • individual access; and
  • challenging compliance.

In addition to general private sector privacy laws, Alberta, Manitoba, Nova Scotia, New Brunswick, Newfoundland and Labrador, Ontario, Québec, and Saskatchewan also have specific health privacy legislation to protect personal health information. For example, Ontario’s Personal Health Information Protection Act, 2004 establishes rules for the collection, use, and disclosure of personal health information by health information custodians in Ontario.

Federal Private Sector Privacy Law — PIPEDA

At the federal level, the Personal Information Protection and Electronic Documents Act (PIPEDA) governs the collection, use, and disclosure of personal information in provinces and in the territories that have not adopted substantially similar privacy legislation, as well as in the course of interprovincial and international commercial activities. PIPEDA applies to all federally regulated works, undertakings, or businesses, regardless of the province in which they operate. This includes entities such as banks, airlines, telecommunications service providers, and other organizations operating under federal jurisdiction.

Unless certain exceptions apply, an individual’s knowledge and consent are required to collect, use, or disclose their personal information. Express consent may be required for more sensitive personal information (e.g., medical or financial information), while implied consent may be sufficient for non-sensitive personal information (e.g., mailing address). The consent of an individual is only meaningful if it is reasonable to expect that an individual to whom the organization’s activities are directed would understand the nature, purpose, and consequences of the collection, use, or disclosure of the personal information to which they are consenting. Exceptions to the “consent” requirement include disclosures of personal information in the context of certain business transactions, as defined in the law.

The Office of the Privacy Commissioner of Canada’s (OPC) Guidelines for Obtaining Meaningful Consent (Guidelines) clarify that failure to obtain meaningful consent may lead a business to lose its ability to handle personal information needed to operate the business. In order to obtain meaningful consent, businesses are encouraged to: (i) ensure that their privacy policy is written in plain language; (ii) use just-in-time privacy notices on their website as a supplement to the longer form privacy policy; (iii) prepare an executive summary of their privacy policy’s key highlights to place at the top of the privacy policy; and (iv) use interactive tools in the presentation of their privacy information.

Provincial Privacy Laws

Alberta, British Columbia, and Québec have adopted their own private sector privacy laws that may apply instead of PIPEDA for both consumer and employee personal information practices of organizations within these provinces. These laws have been deemed substantially similar to PIPEDA. As such, the following section offers a comprehensive overview of Québec’s privacy regime, focusing solely on this province due to the fact that it establishes some of the most stringent requirements applicable in Canada. In other words, complying with Québec’s privacy regime ensures material compliance with other privacy regimes across the country.

Québec

The Act respecting the protection of personal information in the private sector (Québec Act) applies to the collection, use, or disclosure (referred to as ‘communication’) of personal information within the province by ‘any person carrying on an enterprise’. The Québec Act includes several requirements that are unique in Canada and materially more stringent than those found under PIPEDA and other provincial private‑sector laws, including:

Privacy Impact Assessments

Organizations must conduct a privacy impact assessment (PIA) for any project involving the acquisition, development, or overhaul of an information system or electronic service delivery system that involves personal information. This requirement applies broadly and early in the project lifecycle and is not limited to high‑risk use cases.

Before communicating personal information outside Québec, organizations must conduct a PIA specifically assessing whether the information will receive adequate protection in the recipient jurisdiction, taking into account, among other factors, the sensitivity of the information, the purposes for which it is to be used, the applicable protection measures, including those that are contractual, and the legal framework of the recipient jurisdiction. Cross‑border communications must also be governed by written agreements addressing these safeguards.

Confidentiality by Default

Québec has implemented a confidentiality-by-default (“off by default”) regime. Where a public‑facing technological product or service offers privacy settings, those settings must provide the highest level of confidentiality by default, without any action by the user. In practice, optional or privacy‑invasive features must be deactivated unless the user affirmatively opts in. Note that browser cookies are excluded from this regime.

Separately, any person collecting personal information through technology offering identification, location, or profiling functions must inform the individual of those functions and of the means available to activate them. The prevailing interpretation is that, because the legislation speaks of "activating" such functions, they must be delivered in an "off" state by default - the individual must affirmatively choose to turn them on. Unlike the confidentiality by default regime described above, this requirement does extend to browser cookies.

Anonymization

Québec imposes a high standard for anonymization. Personal information is considered anonymized only where it is reasonably foreseeable, at all times, that the information irreversibly no longer allows the individual to be identified, directly or indirectly. In addition, anonymization is subject to continuing governance obligations, including documented methods and criteria, periodic testing of re-identification risk, record-keeping, and re-evaluation over time to ensure the information remains anonymized throughout its lifecycle.

Biometrics

Biometric characteristics and measurements are expressly treated as sensitive personal information, triggering heightened protection and express consent requirements. In addition, Québec’s Act to establish a legal framework for information technology imposes strict obligations on organizations that rely on biometrics to identify or authenticate individuals or that set up biometric databases, including a requirement to notify the Commission d’accès à l’information (CAI) in advance. The CAI may issue broad orders relating to the creation, use, retention, or destruction of biometric databases, including suspension or prohibition measures.

Data Portability

Individuals have a right to request that their computerized personal information be communicated to them, or to another organization, in a structured and commonly used technological format, where such communication is technically feasible.

Automated Decision-Making

The Québec Act imposes specific transparency obligations where personal information is used to render a decision based exclusively on automated processing. Individuals must be informed of the use of automated decision‑making, of the personal information used, and of their right to have the information corrected. Upon request, organizations must also explain the factors and parameters that led to the decision and allow the individual to submit observations to a person capable of reviewing the decision.

Key Trends in Canadian Privacy Laws

Privacy Breach Notifications and Record Keeping

Organizations subject to PIPEDA have reporting, notice, and record retention obligations for any breach of security safeguards. A breach of security safeguards is broadly defined as: “the loss of, unauthorized access to, or unauthorized disclosure of personal information resulting from a breach of an organization’s security safeguards.” Reporting and notification obligations are triggered when there is a real risk of significant harm to an individual (RROSH). RROSH is also broadly defined and includes “bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property.” The factors that are relevant to determine whether a breach creates a RROSH include the sensitivity of the personal information involved in the breach of security safeguards, as well as the probability that the personal information has been, is, and/or will be misused.

The report of the breach to the OPC must be made “as soon as feasible after the organization determines that the breach has occurred.” The same criteria apply for notifying individuals of breaches involving their personal information unless the law provides otherwise.

The notification needs to be conspicuous and contain sufficient information to help affected individuals mitigate the risk of harm. Information regarding what should be included in written reports to the OPC and individual notifications can be found in the Breach of Security Safeguards Regulations. Furthermore, whether or not there is a RROSH, an organization must keep a security-breach log for 24 months following a breach of security safeguards. During this period, organizations must comply with requests from the OPC to have access to the record at any time. Further, an organization encountering a breach will have additional reporting obligations to other organizations and government institutions if the breached organization believes the other organizations may be able to reduce their risk of harm as a result.

The Québec Act and Alberta’s Personal Information Protection Act (Alberta Act) also have privacy breach compliance requirements. In Québec, organizations must notify both the CAI and affected individuals of any breach (referred to in the Québec Act as a “confidentiality incident”) presenting a risk of serious injury, and must maintain a register of all breaches for a period of five years. These obligations are broadly similar to those under PIPEDA, but Québec applies a higher record‑keeping standard (five years rather than two). In Alberta, organizations are required to notify the Office of the Information and Privacy Commissioner of Alberta of breaches if the RROSH threshold is reached (same as with PIPEDA), but individual notification is only required if and when ordered by the Commissioner. In practice, however, many organizations choose to notify affected individuals proactively at the same time as notifying the Commissioner. Unlike Québec and PIPEDA, Alberta does not impose a general breach record‑keeping requirement.

Children’s Privacy

Children’s privacy has emerged as a priority area across Canada, with privacy commissioners and lawmakers emphasizing that children merit heightened protection due to their vulnerability in digital environments. While Canada does not have a standalone children’s privacy statute, existing privacy laws are increasingly interpreted and applied through a child‑protective lens.

Under PIPEDA, consent must be meaningful, and commissioners expect organizations to take into account the age and capacity of the individual when assessing whether meaningful consent has been obtained, with parental consent generally required for younger children.

Across jurisdictions, enforcement activity and regulatory guidance reflect a growing focus on age‑appropriate design, effective age-gating safeguards, limits on profiling and targeted advertising directed at children, and stricter scrutiny of digital services and platforms that are likely to be accessed by minors. As a practical matter, organizations operating in Canada are increasingly expected to treat children’s data as inherently sensitive and to embed protective measures by design when offering services to or likely to be used by children.

Guidelines for Businesses

Whether PIPEDA or similar provincial legislation is the applicable privacy regime, immediate priorities for most organizations that establish a business in Canada should be:

  • the adoption of a documented privacy compliance strategy that identifies the organization’s compliance with the applicable regulatory regimes;
  • the adoption of an external and internal privacy policy, and personal information management practices to ensure compliance with applicable privacy laws;
  • the appointment of an individual who will be responsible for the administration and oversight of the organization’s personal information management practices and who will be prepared to implement any changes required by applicable legislation;
  • a review of the current personal information practices of the organization outside Canada and proposed information practices within Canada, including determining what personal information is collected, and from where; what consents are obtained, and what purposes are identified when collecting personal information; where personal information is stored; how personal information is used; when and to whom personal information is disclosed; and how current personal information practices of the organization may need to be changed for the collection, use, and disclosure of personal information in Canada;
  • a review of the organization’s data management infrastructure to ensure that the infrastructure is adequately flexible and robust to facilitate the implementation of the organization’s privacy policies and data management practices;
  • the implementation of consent language in contracts, forms (including Web forms) and other documents utilized when collecting personal information from individuals (including customers and employees);
  • a review of agreements to ensure that where there are contracts with third parties to whom personal information will be disclosed (or where the third party is granted access to the personal information), that the third party agrees to appropriate contractual terms, such as: specifying the ownership of the data and ensuring that the third party will provide adequate security safeguards for the information; ensuring that the personal information will be used only for the purposes for which it was disclosed to the third party; ensuring that the third party will cease using (and return or destroy) the personal information if requested; and providing for indemnification by the third party for any breach of such terms;
  • the preparation of privacy impact assessments to adequately assess risks to personal information for new projects and cross-border data transfers; and
  • the adoption of a privacy breach response plan that clearly specifies internal contacts and external advisors so that there is no mistake about who is to be contacted for immediate support in the case of an incident. An organization must be able to quickly identify a privacy breach, immediately carry out its plan of action, isolate the affected systems, determine the damage and remediate.

Implementation of such initial steps may require several months, depending on the size and maturity of the organization.

Non-Compliance

Failure to comply with Canadian privacy laws can result in complaints to the relevant privacy commissioner, orders, and fines. An organization with deficient privacy practices may risk adverse publicity for failure to comply with privacy laws.

PIPEDA

PIPEDA does not provide the OPC with order‑making powers or administrative monetary penalties. Enforcement is primarily complaint‑driven and corrective, through investigations, public findings, and, where necessary, applications to the Federal Court. Certain statutory offences (including failures to report or record security breaches) may give rise to penal fines of up to C$100,000 per offence, but monetary sanctions are relatively limited compared to Québec’s regime.

Québec

In Québec, the CAI has broad investigative and order‑making powers, including the ability to require corrective measures to ensure compliance with the Québec Act. The CAI may also impose administrative monetary penalties (AMPs) for non-compliance with the Québec Act of up to C$10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater. The CAI can also institute court proceedings with potential maximum penal fines of up to C$25 million or 4% of worldwide turnover for the preceding fiscal year, whichever is greater. In the case of subsequent non-compliance, fines may be doubled. The CAI’s General Framework for Application of AMPs determines initial fines for various levels of non-compliance, which is used to classify the severity of non-compliance into four categories: minor, moderate, serious, and very serious.

Alberta and British Columbia

Alberta’s and British Columbia’s private‑sector privacy statutes do not include administrative monetary penalty regimes. Instead, the provincial commissioners may investigate complaints and issue binding compliance orders. Failure to comply with the legislation or with an order may constitute an offence and result in court‑imposed fines, generally up to C$100,000 for organizations.

In light of the complexity of privacy laws and the differences between the various laws that may apply to an organization or to a particular business unit, ensuring privacy compliance across an organization’s departments may be challenging, particularly for organizations that operate globally.

It is important to note that these exceptions to consent in case of emergency situations can vary across Canadian privacy statutes and may contain certain conditions. Generally, a notice of disclosure should be given to the individual before or without delay after the fact, if possible. In addition, these legislative authorizations do not always apply to “regular” business operations. Organizations are therefore encouraged to take into account applicable laws, before applying legislative authorizations that provide exemptions to the requirement to obtain consent for the collection, use and disclosure of personal information. 


For a complete view of investment, regulatory and sector considerations, explore the full Doing Business in Canada guide.

Stay up to date on the latest developments in privacy law. Explore our latest Insights.


Get the full Doing Business in Canada guide

Access the complete Doing Business in Canada guide as a downloadable PDF. This comprehensive resource brings together key legal, regulatory and sector-specific considerations to support investment, transactions and operations in the Canadian market.

Download the Full Guide
Get the full Doing Business in Canada guide

People