Privacy Compliance in Canada: Your Questions Answered

Canadian private-sector privacy compliance is still built mainly on PIPEDA, provincial private-sector privacy laws in Quebec, Alberta and British Columbia, and sector-specific rules such as health privacy laws. In June 2026, the federal government introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act, or PPCDA. If passed, it would be the most significant change to Canada’s private-sector privacy law in more than 25 years, but it is not yet in force. Businesses should treat Bill C-36 as a readiness signal, not as current law. The practical work is clear: maintain a privacy management program, know what personal information you collect, assess vendors, document consent, prepare for breach response, and review AI and automated decision systems.

Quebec’s Law 25 can affect organizations outside Quebec if they collect, use, disclose, or store personal information about people in Quebec. It is not a Canada-wide law, but it has become one of the strictest privacy benchmarks in the country. Law 25 requires stronger governance, clear privacy policies, breach handling, confidentiality incident registers, privacy-by-default settings for certain technological products and services, and privacy impact assessments before some cross-border disclosures. Businesses with Quebec customers, users, employees, students, patients, or donors should not treat Law 25 as optional. It deserves its own compliance checklist, not a footnote in a general Canadian privacy policy.

A Privacy Impact Assessment is not automatically mandatory for every Canadian small business, but it is increasingly expected when privacy risk is material. You should conduct a PIA before launching new software, using AI or automated decision systems, transferring sensitive personal information to vendors, sending personal information outside Canada or outside Quebec, or changing how personal information is collected, used, disclosed, retained, or deleted. Quebec Law 25 requires a privacy impact assessment before communicating personal information outside Quebec. Bill C-36 would also require privacy impact assessments in important situations, including certain legitimate-interest uses and transfers outside Canada. A PIA is the difference between guessing and proving due diligence.

PIPEDA’s 10 fair information principles are the foundation of Canadian private-sector privacy compliance: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. They are not academic concepts. They are the operating model for a privacy program. A business should be able to show who is accountable for privacy, why personal information is collected, how consent is obtained, how information is protected, how long it is retained, how access requests are handled, and how complaints are managed. The Office of the Privacy Commissioner of Canada continues to frame business privacy responsibilities around these principles, meaningful consent, and privacy breach obligations.

Bill C-36 would introduce a much stronger enforcement regime for federal private-sector privacy law if passed. The government says the proposed law would allow administrative monetary penalties up to $10 million or 3% of global revenue, whichever is greater, and fines up to $25 million or 5% of global revenue, whichever is greater, for the most serious offences. The bill would also create a new Digital Safety and Data Protection Commission of Canada, with a designated Privacy and Consumer Data Commissioner responsible for PPCDA oversight. For now, organizations should not present these penalties as current law, but they should prepare as if stronger enforcement is coming.

Canada does not currently have one simple, universal private-sector “right to be forgotten.” Under existing privacy law, individuals can withdraw consent subject to legal or contractual limits, and in some cases that may require an organization to stop using or delete personal information. Bill C-36 would go further by allowing individuals to request deletion or disposal of their personal information in certain circumstances. Businesses should prepare now by mapping where personal information lives, documenting retention periods, defining legal holds, and creating a repeatable intake process for access, correction, deletion, and complaint requests. Deletion is not a button. It is an evidence trail.

Canadian privacy law requires meaningful consent for the collection, use, and disclosure of personal information. For websites, that means users should understand what information is collected, why it is collected, who it is shared with, and what risks or consequences may follow. Implied consent may be appropriate for some low-risk, expected uses, but express consent is safer for sensitive information, unexpected uses, profiling, behavioural advertising, location tracking, or sharing with third parties. Do not bury tracking practices in a long privacy policy and call it consent. Use clear notices, plain language, consent records, and easy withdrawal. In Quebec, Law 25 adds stricter requirements for certain tracking and profiling technologies.

Privacy by Design means privacy is built into a process, product, service, contract, or system before personal information is collected. In practical terms, it means collecting less data, explaining purposes clearly, using privacy-protective defaults, limiting access, assessing vendors, encrypting sensitive records, defining retention periods, training staff, and preparing for breach response before there is a crisis. Under Quebec Law 25, certain technological products or services must provide the highest level of confidentiality by default, without user intervention, except for browser cookie settings. Bill C-36 would also raise expectations for privacy management programs, safeguards, transparency, children’s data, automated decisions, and cross-border transfers.

AI does not remove privacy obligations. It multiplies them. Canadian organizations using AI must still comply with existing privacy laws, including PIPEDA and applicable provincial laws. That means identifying purposes, limiting collection, obtaining meaningful consent where required, safeguarding personal information, assessing vendors, and avoiding inappropriate uses. Bill C-36 would increase transparency around automated decision systems, including AI-powered systems, and would require organizations to explain certain predictions, recommendations, or decisions that have legal or similarly significant effects on individuals. AIDA should be removed from this FAQ because Bill C-36 does not revive it as a stand-alone AI law.

Managed Privacy Canada helps organizations turn privacy obligations into a practical operating program. That includes privacy impact assessments, privacy audits, vendor privacy assessments, breach-readiness planning, privacy policies, consent reviews, data inventory work, staff training, executive reporting, and managed privacy support through PrivacyDash and Verify RPM. For Bill C-36 readiness, organizations should start by mapping personal information, identifying sensitive and children’s data, reviewing automated decision systems, assessing cross-border transfers, documenting retention and disposal practices, and strengthening breach records. The goal is not to look compliant for a day. The goal is to be able to prove privacy responsibility when a customer, regulator, board, insurer, or procurement team asks.

Canadian privacy law does not impose a simple universal rule that all personal information must be stored only in Canada. The real obligation is to know where personal information goes, assess the risk, inform individuals where required, use appropriate contractual safeguards, and protect the information throughout its lifecycle. Quebec Law 25 requires a privacy impact assessment before communicating personal information outside Quebec. Bill C-36 would require organizations to assess and mitigate privacy risks before sending personal information outside Canada. Canadian hosting may be appropriate for some sensitive, public-sector, health, contractual, or high-risk data, but do not present it as a universal private-sector legal requirement.

Data mobility means an individual could ask one organization to transfer personal information to another organization in a structured, secure way, but only where a data mobility framework applies. Bill C-36 would support data mobility so Canadians can move information securely between organizations where the framework applies. The bill says organizations would have to disclose personal information collected from the individual to another designated organization if both organizations are subject to a data mobility framework. This is not yet a general current PIPEDA obligation. Businesses should prepare by improving data inventories, access-request workflows, interoperability planning, authentication, and secure transfer controls.

Quebec Law 25 requires any person carrying on an enterprise who collects personal information when offering a technological product or service to the public with privacy settings to ensure that those settings provide the highest level of confidentiality by default, without intervention by the individual. The law expressly says this privacy-by-default rule does not apply to browser cookie privacy settings. This matters for apps, platforms, portals, dashboards, learning tools, health tools, customer accounts, and other digital services with user-configurable privacy settings. Do not describe this as a general Canada-wide requirement. It is a Quebec requirement that often becomes a practical national design standard.

No. Bill C-36 does not replace AIDA with a new stand-alone AI law. AIDA was part of the earlier Bill C-27 package and should not be presented as current Canadian law. The federal government has now separated privacy reform from stand-alone AI regulation. Bill C-36 focuses on privacy and consumer data, including transparency for automated decision systems. Bill C-34 separately proposes rules for social media services and certain AI chatbot services, especially where children’s safety and online harms are concerned. For businesses, the practical path is to govern AI through privacy law, vendor risk, security assessment, human oversight, transparency, data minimization, and documented risk assessment.

Yes, but the exact obligation depends on the law that applies. Under Quebec Law 25, enterprises must keep a register of confidentiality incidents and send a copy to the Commission d’accès à l’information on request. Under federal privacy law, organizations must also be able to document breaches of security safeguards. Bill C-36 would require organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control and provide the record to the new Commission on request. A good breach record should capture what happened, what information was involved, who was affected, risk of harm, containment steps, notifications, decisions, and corrective actions.

Wondering how privacy can enhance your business?