TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL·TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL
🇨🇦

Canada Data Privacy Regulations

Personal Information Protection and Electronic Documents Act (PIPEDA)
Medium Severity
Enacted: 2000 (Amended: 2015 (Digital Privacy Act))

Overview

PIPEDA applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity, relying on 10 fair information principles. (Soon to be replaced/upgraded by CPPA under Bill C-27).

Scope of Application:

Private-sector organizations collecting personal information in commercial activities, excluding provinces with "substantially similar" legislation (e.g., Quebec, BC, Alberta).

Key Rules & Obligations

Breach Notification

As soon as feasible after determining the breach presents a real risk of significant harm (RROSH).

Maximum Penalties

Up to $100,000 CAD per violation for failure to report or maintain breach records.

Data Transfers

Organizations are accountable for data processed by third parties, including cross-border transfers.

Individual Rights

  • Right to access
  • Right to challenge accuracy
  • Right to withdraw consent

Enforcement Authority

Office of the Privacy Commissioner of Canada (OPC)

Contact: 1-800-282-1376

Visit Authority Website

Notable Breaches in Canada

CompanyYearRecords ExposedRegulation Violated
Desjardins20199,700,000PIPEDA & Quebec laws
LifeLabs201915,000,000PIPEDA & Provincial laws

Official Sources

Frequently Asked Questions

Is PIPEDA replacing GDPR in Canada?

PIPEDA is Canada's federal private sector privacy law.It is older than GDPR and operates mostly on an opt- out consent model, though Canada is currently drafting new privacy legislation(Bill C - 27) to modernize it.

Does every Canadian province follow PIPEDA?

No. Alberta, British Columbia, and Quebec have their own private-sector privacy laws that are deemed substantially similar to PIPEDA. Quebec's Law 25 is currently Canada's strictest regime.

How do I report a data breach in Canada?

Organizations must file a breach report with the OPC as soon as feasible if it creates a real risk of significant harm.

Last updated: March 5, 2026

Notice an error? Report a correction