PIPEDA, Law 25 and GDPR: A Privacy Map for Canadian Startups

Parliament Hill in Ottawa, where Canadian privacy law is made

A Canadian startup with customers in Montreal, Vancouver and Berlin is subject to at least four privacy regimes at once, and they disagree about when you have to tell anyone that something went wrong. Quebec’s Law 25 is the one with teeth, PIPEDA is the one with the weakest enforcement, and the federal government is trying again to replace it. Here is how the pieces fit as of September 2026.

PIPEDA: the federal baseline and its enforcement gap

The Personal Information Protection and Electronic Documents Act governs personal information handled in the course of commercial activity. It applies to federal works, undertakings and businesses everywhere in Canada, and, as the Office of the Privacy Commissioner explains in its guidance on the interaction between PIPEDA and the provincial acts, “trans-border personal information flows in a commercial context are covered by PIPEDA” because federal authority extends to interprovincial and international commerce. For a SaaS company that means PIPEDA reaches you the moment data crosses a provincial or national border, which for anything hosted in a US region is immediately.

Breach duties sit in the safeguards provisions. Under the OPC’s guidance on mandatory reporting of breaches of security safeguards, you must report to the Commissioner and notify affected individuals when it is reasonable to believe the breach “creates a real risk of significant harm.” The test turns on the sensitivity of the information and the probability it will be misused. Notification must happen “as soon as feasible” once you have made that determination; there is no fixed clock. You must keep records of every breach, reportable or not, for 24 months. The OPC has published a self-assessment tool to help work through the harm threshold.

The enforcement gap is the important part. Knowingly contravening the reporting, notification or record-keeping rules is an offence that can lead to fines, but the OPC cannot levy them. It refers matters to the Attorney General of Canada for prosecution by the Director of Public Prosecutions. In practice, PIPEDA’s operative sanction has been a published finding of non-compliance.

Quebec’s Law 25: the regime that actually bites

Law 25, the Act to modernize legislative provisions as regards the protection of personal information, applies to any private-sector enterprise handling the personal information of people in Quebec, regardless of where the enterprise sits. Its enforcement scheme came into force on 22 September 2023 with three separate exposures:

  • Administrative monetary penalties imposed by the Commission d’accès à l’information, up to the greater of C$10 million or 2% of worldwide turnover for the preceding fiscal year.
  • Penal fines up to the greater of C$25 million or 4% of worldwide turnover, with a minimum of $15,000 for corporations, a five-year limitation period, and the possibility of doubled fines for repeat offences.
  • A private right of action. Section 93.1 provides statutory punitive damages of at least $1,000 where an unlawful infringement of privacy rights causes harm and the conduct was intentional or grossly negligent. Actual harm and causation still have to be proven, but a $1,000 statutory floor multiplied across a class is a materially different litigation risk from anything PIPEDA creates.

Breach handling is stricter too. The Commission d’accès à l’information’s guidance for private businesses requires notification to the CAI and to affected individuals when a confidentiality incident “presents the risk that serious injury be caused,” assessed on the sensitivity of the information, the expected consequences of its use, and the probability it will be used for harmful purposes. Separately, every business must maintain a register of all confidentiality incidents, whatever the severity, and keep entries for a minimum of five years. Companies that decide no serious injury risk exists still have to reduce risk and prevent recurrence; they simply do not have to notify.

Other Law 25 obligations bite on product design rather than incident response: a designated privacy officer, privacy impact assessments before communicating personal information outside Quebec, consent that is requested separately for each purpose and in clear language, an obligation to publish a privacy policy in plain terms, and privacy-by-default settings for technology that collects personal information. The data portability right, letting individuals demand computerised personal information in a structured, commonly used technological format, took effect on 22 September 2024.

Alberta and British Columbia

Alberta and BC each have a Personal Information Protection Act that the Governor in Council has declared substantially similar to PIPEDA, so provincially regulated organisations in those provinces follow the local act for intra-provincial activity. The OPC is clear that this does not displace PIPEDA entirely: cross-border and interprovincial commercial flows remain federal. The practical consequence for a startup is that you comply with the strictest applicable rule rather than picking one act.

The breach rules diverge sharply, and this is the difference founders most often get wrong. Alberta’s PIPA carries a mandatory notification duty: organisations must notify the Information and Privacy Commissioner of Alberta and affected individuals, without unreasonable delay, where a breach meets a real risk of significant harm threshold. BC’s PIPA, as counsel at Burnet, Duckworth & Palmer summarise, does not currently mandate breach notification for private-sector organisations, though the BC Commissioner recommends voluntary notification as good practice.

GDPR: it reaches further than most founders assume

Article 3(2) of the GDPR applies to controllers with no EU establishment where they offer goods or services to data subjects in the EU, or monitor their behaviour. The European Data Protection Board’s Guidelines 3/2018 on territorial scope set out the targeting analysis: a website merely being accessible from Europe is not enough, but pricing in euros, EU-language versions, EU-targeted advertising, an EU top-level domain, EU delivery or EU phone support are the kinds of factors that establish intent to target. Behavioural monitoring, including analytics and ad tracking of EU visitors, is a separate hook that catches products with no EU marketing at all.

If Article 3(2) applies, Article 27 generally requires you to designate a representative in the Union, and Article 33(1) requires notification to the supervisory authority “without undue delay and, where feasible, not later than 72 hours after having become aware of it.”

Breach clocks side by side

Regime Threshold Regulator notice Individual notice Record keeping
PIPEDA Real risk of significant harm As soon as feasible; no fixed deadline As soon as feasible All breaches, 24 months
Quebec Law 25 Risk of serious injury Promptly, to the CAI Promptly All incidents, minimum 5 years
Alberta PIPA Real risk of significant harm Without unreasonable delay, to the Alberta OIPC As directed by the Commissioner Per Commissioner guidance
GDPR Risk to rights and freedoms 72 hours where feasible Where high risk, without undue delay All breaches documented

Design your incident process to the tightest constraint you are exposed to. If you have any EU users, that is 72 hours, and Quebec’s “promptly” is not meaningfully looser. Building a 72-hour pipeline once is cheaper than maintaining four.

Federal reform, third attempt

Bill C-27 and its Consumer Privacy Protection Act died when Parliament was prorogued in January 2025. Reform returned on 15 June 2026, when Bill C-36 received first reading. As Fasken’s analysis notes, the bill would enact the Protecting Privacy and Consumer Data Act and replace Part 1 of PIPEDA. Reported features include mandatory privacy management programmes open to regulator review, privacy impact assessments before cross-border transfers, a legitimate-interests basis as an alternative to consent, a right to human review of automated decisions with legal or similarly significant effect, enhanced protection for children’s information, and disposal rights. Administrative monetary penalties would run to the greater of C$10 million or 3% of gross global revenue, with offences reaching the greater of C$25 million or 5%.

At the time of writing the bill has only had first reading and committee amendments are expected, so nothing in it is a compliance obligation yet. Two of the last three attempts did not survive a Parliament.

What to build now, in order

Build the Quebec-grade programme and you have covered the rest. Appoint a named privacy officer and publish the role. Write a data inventory that records, per data element, where it is stored, which subprocessor touches it and which country it sits in, because both Law 25 transfer assessments and GDPR records of processing depend on that one artefact. Stand up a confidentiality incident register today and log everything, since Quebec’s five-year retention is the longest requirement you face and back-filling it is impossible. Rewrite consent so each purpose is requested separately in plain language, and default new collection settings to the most protective option. Then write one incident runbook with a 72-hour clock, name the humans who decide whether the harm threshold is met, and rehearse it once. The obligations in Bill C-36, if it passes, map almost entirely onto that work.

Sources

Post Comment