GDPR Compliance

GDPR for Canadian Companies: Does It Apply to You?

Canada's adequacy decision does not exempt Canadian companies from the GDPR. When Art. 3(2) applies, the Art. 27 EU representative duty, and what health data changes.

Start with the point that derails most Canadian assessments. Canada holds a partial adequacy decision from the European Commission — Decision 2002/2/EC of 20 December 2001, kept alive under Art. 45(9) GDPR — and it covers recipients in Canada that are subject to PIPEDA. Canadian companies read that and conclude the GDPR does not reach them. It does not follow, and the two questions are not even about the same party.

Adequacy answers: may a European company send personal data to you without extra safeguards? Article 3 answers: does the GDPR bind you directly, as a controller or processor, for your own processing? A Toronto telehealth platform with paying users in Ireland is caught by Art. 3(2) whether or not Canada is adequate. Adequacy is a transfer mechanism for the exporter’s benefit. It is not a jurisdictional shield, and no adequacy decision has ever removed a single obligation from a company established outside the EU.

Key Takeaways

  • Canada’s adequacy decision is partial and concerns transfers into Canada. It does not exempt a Canadian controller from the GDPR.
  • Art. 3(2) catches Canadian companies that offer goods or services to people in the EU or monitor their behaviour, with no employee-count or revenue threshold.
  • Most in-scope Canadian companies must designate an EU representative in writing under Art. 27 and name it in the privacy notice.
  • Health data is Art. 9 special-category data: scope is only the entry point, and a DPIA is effectively mandatory.
  • A medical device manufacturer’s Authorised Representative under Art. 11 MDR does not satisfy Art. 27 GDPR. They are separate appointments under separate regulations.

The Two Routes Into Scope

Art. 3(1): an establishment in the Union

If your Canadian company has a subsidiary, branch, sales office or even a single stably employed person in a member state, the GDPR applies to processing carried out “in the context of the activities of” that establishment. The CJEU reads this broadly: in Google Spain (C-131/12, 13 May 2014) a Spanish advertising subsidiary was enough to pull the entire search operation into EU jurisdiction, although the processing ran on US servers. A Vancouver medtech company with two clinical liaison staff in Germany is well past the line.

Art. 3(2): targeting or monitoring

Without any EU presence, the GDPR still applies where processing relates to (a) offering goods or services to individuals in the Union, or (b) monitoring their behaviour in the Union. Recital 23 is clear that a website merely being reachable from Europe is not enough — there must be an intention to target. Recital 24 treats internet tracking and profiling as monitoring. Our guide on whether the GDPR applies outside the EU works through the general test; what follows is what changes when the company is Canadian.

Two Canadian traps. First, French-language content proves nothing. The EDPB Guidelines 3/2018 on territorial scope list use of a language of a member state as a targeting indicator, but a bilingual Canadian site serving Quebec is complying with domestic obligations, not courting Lyon. Second, a .ca domain does not protect you either — the indicators are cumulative and behavioural, not formal.

What actually moves the needle: prices quoted in euros, an EU shipping or service option, a member-state phone number, EU-targeted paid acquisition, EU customer references in your marketing, a data protection contact address in Europe, or an app store listing localised for EU markets.

Worked examples.

Ottawa digital-health platform, subscription mental-health service, 900 users in France, Belgium and Ireland, checkout in EUR. In scope under Art. 3(2)(a) — and the data is health data, so see below.

Montreal SaMD vendor whose software is bundled with a device sold through an EU distributor, with the vendor collecting patient telemetry directly from the device. In scope: the telemetry processing relates to a service offered to individuals in the Union, and it is also monitoring under Art. 3(2)(b).

Toronto CRO recruiting trial participants in Spain and Poland on behalf of a Canadian sponsor. In scope, and jointly exposed on the Art. 9 conditions and the DPIA.

Calgary industrial parts distributor selling only to North American buyers, English-only site, CAD pricing, no EU shipping, and a German engineer who happens to browse it. Not in scope. Accessibility is not targeting.

Halifax analytics vendor whose SDK is embedded in an EU publisher’s app and builds behavioural profiles of readers in Italy. In scope under Art. 3(2)(b), regardless of the fact that its customer, not the reader, pays it.

Location, not nationality. Art. 3(2) protects individuals in the Union at the moment of processing. A Canadian citizen living in Calgary is not covered because they hold an EU passport; a Canadian on a six-month posting in Amsterdam may be.

Health Data Raises Every Threshold

For Canadian health and life-sciences companies, Art. 3(2) is the entry ticket, not the exam. Health data, genetic data and biometric data used for identification are special categories under Art. 9(1), and processing them is prohibited unless one of the Art. 9(2) conditions applies in addition to an Art. 6 lawful basis. Two bases, not one — explicit consent under Art. 9(2)(a), or a research, public-health or healthcare-provision condition, most of which depend on member-state law that varies country by country.

A DPIA is effectively mandatory: Art. 35(3)(b) names large-scale processing of Art. 9 data as a case requiring one. And Art. 83(5) puts breaches of Arts. 5, 6, 7 and 9 in the higher fine band — up to EUR 20 million or 4% of worldwide annual turnover.

Layer that onto the Canadian position. A telehealth provider in Ontario is a health information custodian under PHIPA; the same company’s EU-facing service is a GDPR controller processing Art. 9 data; if it operates in Quebec it also sits under Law 25’s stricter consent and impact-assessment rules. Three regimes with three vocabularies over one dataset. Our comparison of PIPEDA and the GDPR maps where they diverge.

The Art. 27 EU Representative

If Art. 3(2) applies and you have no establishment in the Union, Art. 27(1) requires you to designate a representative in the EU in writing, established in a member state where your data subjects are located. The representative is a contact point for supervisory authorities and individuals under Art. 27(4), and its identity and contact details belong in your privacy notice under Arts. 13 and 14.

Art. 27(2) exempts processing that is occasional, excludes large-scale Art. 9 or Art. 10 data, and is unlikely to result in a risk to rights and freedoms — three conditions, all of which must hold. A health platform with EU users fails the second immediately. Failure to designate is itself an infringement under Art. 83(4)(a), carrying up to EUR 10 million or 2% of turnover, and it is the easiest finding a regulator can make: either a name appears in your privacy policy or it does not. Our detailed treatment of Art. 27 and the practical guide to choosing an EU representative cover selection and mandate drafting.

The MDR representative is a different appointment

Canadian medical-device manufacturers already know the role of an Authorised Representative. Under Art. 11 of Regulation (EU) 2017/745 (MDR) — and Art. 11 of Regulation (EU) 2017/746 for in vitro diagnostics — a manufacturer without a registered place of business in a member state may place a device on the Union market only if it designates a sole authorised representative under a written mandate, who verifies the EU declaration of conformity, keeps the technical documentation available, registers the device and cooperates with competent authorities.

That appointment does nothing for the GDPR. Different regulation, different trigger (placing a product on the market versus processing personal data), different tasks, different liability regime, and usually a different provider. Regulatory-affairs firms that supply MDR representation are not automatically willing or competent to act as an Art. 27 representative, and a mandate drafted for the MDR does not cover supervisory-authority correspondence about a data subject access request. Treat them as two contracts.

What Compliance Actually Requires

Being in scope means the full controller regime, with no lighter tier for foreign companies. A lawful basis for every activity, plus an Art. 9 condition for health data. Transparency under Arts. 13-14. Data subject rights answered within one month, time zones notwithstanding. A record of processing activities under Art. 30 — PIPEDA has no equivalent, which is why this is usually the largest single gap. Written processor contracts under Art. 28 with every vendor touching EU data. Security measures under Art. 32. And a 72-hour breach notification capability that runs on a different clock from the OPC’s “as soon as feasible” standard.

Where EU personal data flows onward from Canada to a third country — a US sub-processor, an offshore support desk — Chapter V applies again and the Canadian adequacy decision does not travel with the data. Transfers in the other direction are covered in our analysis of Canada-EU data transfers, including the categories that fall outside adequacy entirely.

Tooling matters here mainly because the documentation has to survive an audit rather than a self-assessment; we compare the options in GDPR compliance software for Canadian companies.

FAQ

Does Canada’s adequacy decision mean the GDPR does not apply to us?

No. Decision 2002/2/EC lets an EU exporter transfer personal data to a Canadian recipient subject to PIPEDA without additional safeguards. It says nothing about whether the GDPR applies to your own processing. If Art. 3(1) or Art. 3(2) is triggered, you are a controller or processor under the GDPR with all the corresponding duties, adequacy or not.

We are a small Canadian company with 40 EU customers. Is there a threshold?

There is no size threshold in Art. 3. The only size-related relief is Art. 30(5), which narrows the record-keeping duty for organisations under 250 employees — and it does not apply where processing is regular, likely to result in risk, or involves Art. 9 data. Health and trial data cancels it.

Can EU authorities actually enforce against a Canadian company?

They can and do act against non-EU companies. The CNIL fined Clearview AI EUR 20 million (Deliberation SAN-2022-019, 20 October 2022) despite the company having no EU establishment and refusing to engage. In Canada, the same company was found in contravention of PIPEDA in a joint investigation by the OPC and the Quebec, British Columbia and Alberta commissioners (PIPEDA Findings #2021-001, 2 February 2021). Regulators on both sides cooperate, and the commercial cost usually arrives before the fine does — through EU customers who cannot lawfully buy from a supplier with no representative and no transfer file.

Does our MDR Authorised Representative cover Art. 27?

No. Art. 11 MDR and Art. 27 GDPR are separate obligations under separate regulations with different tasks. You need both appointments, and in practice two different providers. Check your MDR mandate: it almost certainly excludes data protection correspondence.

Where do we start?

Decide the Art. 3 question in writing and keep the reasoning. Then map every processing activity involving EU personal data into an Art. 30 record, identify the Art. 9 conditions you rely on, designate the Art. 27 representative and publish it, and put Art. 28 contracts in place with your vendors. That order matters: the record tells you how large the rest of the problem is before you buy anything to solve it.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →