Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is partial. It covers a defined slice of Canadian organisations, and a transfer to a Canadian recipient outside that slice needs an Art. 46 safeguard exactly as if Canada had never been recognised at all.
This page sets out the boundary precisely, because getting it wrong is a Chapter V infringement on the exporter’s side and a failed vendor assessment on the Canadian side.
Key Takeaways
- Commission Decision 2002/2/EC (20 December 2001) recognises Canada as adequate only for recipients subject to PIPEDA.
- The decision predates the GDPR and survives under Art. 45(9); it has no fixed expiry, but the Commission monitors it and confirmed it in a January 2024 review.
- Public bodies, non-commercial organisations and much employee data fall outside PIPEDA, and therefore outside adequacy.
- Where adequacy does not reach, use the 2021 Standard Contractual Clauses with the correct module and a transfer impact assessment.
- Adequacy covers the transfer. It does not exempt the Canadian recipient from any GDPR obligation of its own.
What the Decision Actually Says
Decision 2002/2/EC was adopted under Art. 25(6) of Directive 95/46/EC and found that the Personal Information Protection and Electronic Documents Act provides adequate protection for personal data transferred from the Community to recipients subject to that Act. When the GDPR replaced the Directive, Art. 45(9) preserved existing adequacy decisions in force until amended, replaced or repealed.
The operative words are “subject to PIPEDA”. PIPEDA applies to the collection, use or disclosure of personal information in the course of commercial activities by private-sector organisations, and — for employee information — only to federal works, undertakings and businesses.
That produces four categories of Canadian recipient the adequacy decision does not reach.
1. Federal, provincial and municipal public bodies. Federal institutions are governed by the Privacy Act, not PIPEDA. Provincial and municipal bodies are governed by provincial public-sector statutes. A European university sending research data to a provincial ministry, or a European agency sharing data with a Canadian public authority, cannot rely on 2002/2/EC.
2. Non-commercial activity. Non-profits, charities, professional associations, political parties and most academic institutions are outside PIPEDA unless the specific activity is commercial. This is the trap for research collaborations: a Canadian public hospital or university research institute receiving EU clinical trial data is not engaged in commercial activity and is not a PIPEDA-covered recipient. Adequacy does not apply. Neither does it apply to an academic biobank or a non-profit registry.
3. Employee data outside federally regulated sectors. PIPEDA’s employee-information provisions bite only on federal works, undertakings and businesses — banks, airlines, railways, telecommunications, broadcasting, interprovincial transport. An EU parent transferring HR records to its Canadian manufacturing or software subsidiary is transferring employee data that PIPEDA does not govern, so the transfer sits outside adequacy. This is probably the single most common Canadian adequacy error in EU-headquartered groups.
4. The margins of the provincial substantially-similar orders. Quebec, Alberta and British Columbia have private-sector statutes designated substantially similar, and organisations in those provinces are exempted from PIPEDA in respect of activity occurring within the province. Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have equivalent designations for health information custodians under statutes such as PHIPA. The exemption orders are drafted narrowly: PIPEDA continues to apply to personal information exchanged across provincial borders and to information transferred outside Canada. So an international transfer to a commercial recipient in Quebec or Ontario generally remains within PIPEDA — and within adequacy — while what happens to the data afterwards inside the province is governed by provincial law.
What is not a limit. Adequacy is not conditioned on the recipient’s size, sector or certification, and there is no register to check. The test is legal coverage, not enrolment. That is a meaningful difference from the EU-US framework, where certification status is checkable and can be withdrawn — a distinction we set out in the BCR, SCC and DPF comparison.
The Review Position
Decision 2002/2/EC carries no expiry date. Adequacy decisions adopted under the GDPR are subject to periodic review under Art. 45(3), and Art. 45(4) obliges the Commission to monitor developments in third countries on an ongoing basis, with the power to amend, suspend or repeal under Art. 45(5).
In January 2024 the Commission published its report on the first review of the eleven adequacy decisions adopted under the Directive, and concluded that all of them, Canada included, should remain in place. The review noted PIPEDA’s development through OPC guidance and Federal Court jurisprudence. It also took place against the background of stalled federal reform: Bill C-27 died on prorogation on 6 January 2025 and, as of 30 July 2026, no replacement has been enacted. Adequacy stands. It is not permanent, and it is worth re-checking the Commission’s published list before a long-term architecture decision. Our comparison of PIPEDA and the GDPR covers the reform track in more detail.
When You Need SCCs Anyway
Where the recipient is outside PIPEDA’s scope, the exporter needs an Art. 46 safeguard. In practice that means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which are modular:
| Module | Configuration | Typical Canadian case |
|---|---|---|
| 1 | Controller to controller | EU sponsor sharing data with a Canadian research institute acting on its own purposes |
| 2 | Controller to processor | EU controller using a Canadian SaaS or service provider outside PIPEDA |
| 3 | Processor to processor | Canadian sub-processor engaged by an EU processor |
| 4 | Processor to controller | EU processor returning data to a non-EU controller |
Our guide to the standard contractual clauses covers annex drafting and the docking clause. Clause 14 requires the parties to assess whether local law and practice prevent the importer from meeting its commitments — the transfer impact assessment. For Canada that assessment is comparatively short, since the Commission’s own adequacy finding does much of the work on the private-sector side, but it is not automatic where the recipient is a public body or where Canadian law enforcement access is realistically in play. The catalogue of supplementary measures sets out the technical options where the assessment is not clean.
Two further situations require SCCs even where adequacy would otherwise apply. Onward transfers: if the Canadian recipient sends the data to a US or offshore sub-processor, that leg needs its own Chapter V basis and the Canadian adequacy decision does not travel with it. Contractual insistence: many EU customers now require SCCs as a matter of procurement policy regardless of adequacy, particularly in health and financial services. Signing them costs nothing legally and closes the deal.
The Direction People Forget
Adequacy governs data moving into Canada. It has nothing to say about a Canadian company’s own obligations, and it does not answer the question Canadian readers usually mean. If your Canadian company offers goods or services to people in the EU or monitors their behaviour, Art. 3(2) applies directly and you owe the full controller regime, including an Art. 27 representative. We set out that test in GDPR for Canadian companies and in the general treatment of whether the GDPR applies outside the EU.
Nor does adequacy remove the Quebec-side duty running the other way: before communicating personal information outside Quebec, a Law 25 organisation must assess whether the information will receive adequate protection and put the communication under a written agreement. Two assessments, two directions, one data flow.
Where the volume of these files becomes unmanageable by spreadsheet — transfer registers, per-vendor modules, annex versions, TIA evidence — see our review of GDPR compliance software for Canadian companies and the framework in Art. 44 on transfers to third countries.
FAQ
Do we need SCCs to send EU personal data to a Canadian company?
Not if the recipient is subject to PIPEDA for that processing — which covers most private-sector commercial recipients. You do need them if the recipient is a public body, a non-profit or research institute acting non-commercially, or if the data is employee data going to an organisation that is not a federal work, undertaking or business.
Our Canadian vendor is in Quebec. Does Law 25 displace adequacy?
No. The provincial exemption orders remove PIPEDA only for activity occurring within the province; PIPEDA continues to apply to information crossing provincial or national borders, which is what an EU transfer is. Document the reasoning rather than assuming it, and expect the Quebec entity to have its own outbound assessment duty for anything it sends on.
Is the Canadian adequacy decision under threat?
It was reviewed and maintained in January 2024. The Commission monitors continuously under Art. 45(4) and can suspend or repeal. Stalled federal reform is a known factor in the assessment. Check the Commission’s adequacy list before committing to an architecture that would be expensive to unwind.
Can we rely on adequacy for clinical trial data going to a Canadian hospital?
Usually not. A public hospital or university research institute is not processing in the course of commercial activity and so is not a PIPEDA-covered recipient. Use SCCs — Module 1 where the site is an independent controller, Module 2 where it acts on the sponsor’s instructions — and remember that health data is Art. 9 special-category data, so the underlying processing needs an Art. 9 condition as well as a transfer mechanism.
Does adequacy mean the Canadian recipient has no GDPR obligations?
No. Adequacy legitimises the exporter’s transfer. If the recipient is itself caught by Art. 3, or is bound as a processor through an Art. 28 contract, those obligations stand independently.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial




