

In this article we cover the basics for PIPEDA Compliance.
If your business operates in Canada, PIPEDA oversees what you can do with the personal data you collect from consumers.
Primarily, the Personal Information Protection and Electronic Documents Act (PIPEDA) is a Canadian federal regulation that covers companies operating in the private sector. It controls how;
Explore more privacy compliance insights and best practices
Who Needs to Comply with PIPEDA
It is important to highlight the fact that PIPEDA does not explicitly outline its applicability in relation to foreign companies.
Nonetheless, some international firms have been penalized for violating PIPEDA requirements, which sets a clear precedent for foreign organizations to become compliant or face similar consequences.
What is Personal Information of PIPEDA?
Under PIPEDA, personal information refers to ‘any information about an identifiable individual.’
The categories of data considered personal information under PIPEDA include;
However, there are specific categories of data that do not fall under the scope of PIPEDA. They include;
Which Consumer Rights does PIPEDA Protect?
Canada’s data privacy law grants consumers the right to;
Apart from guaranteeing consumer rights, PIPEDA outlines the responsibility of businesses in protecting personal data. Essentially, businesses are expected to;
What are the Penalties for Non-Compliance?
The latest amendments to PIPEDA now come with fines of up to $100,000 for companies that fail to meet data protection obligations.
While this isn't nearly as onerous as GDPR, it's likely to be only the start for more stringent enforcement of PIPEDA.
What Do the Latest Amendments Mean for Data Breach Notification Rules?
As of November 1, 2018, organizations subject to PIPEDA that experience a data breach need to determine whether the access or loss of personal information can cause a "risk of significant harm" to individuals.
The new provisions were approved back in 2015 as part of S-4, the nation's Digital Privacy Act
Under the new amendments, in order to comply with PIPEDA, organizations must:
For additional queries or concerns, book a call with us today for personalized support on how to make your company and website compliant with PIPEDA. Check out how to have a PIPEDA-compliant cookie banner.
Check out the 10 PIPEDA Principles here.
Learn about the Bristish Columbia Personal Information Privacy Act, Quebec's Bill 64, and the newly proposed Consumer Privacy Protection Act - CPPA.