Data Privacy

PIPEDA vs GDPR: What Canadian Businesses Must Know

PIPEDA's ten principles against the GDPR's structure: consent, erasure, breach reporting to the OPC, Quebec Law 25, enforcement powers and the state of federal reform.

PIPEDA and the GDPR are not two versions of the same law. They were built on different premises, they allocate risk differently, and a Canadian company that is compliant with one is measurably short of the other. The gap is not stylistic. It is a set of specific documents, workflows and rights that PIPEDA never asks for.

The European Commission has confirmed that Canada continues to provide an adequate level of protection for data transferred to organisations subject to PIPEDA, most recently in its January 2024 report on the first review of the pre-GDPR adequacy decisions. Adequacy is a finding about the protection given to imported data. It is not a statement that the two laws are equivalent, and no non-EU statute is. If the GDPR applies to you directly — see our analysis of when the GDPR reaches Canadian companies — you comply with the GDPR on its own terms.

Key Takeaways

  • PIPEDA is principles-based with a reasonableness standard; the GDPR is rule-based with six enumerated lawful bases.
  • PIPEDA has no general right to erasure, no portability right and no ROPA obligation.
  • Breach reporting differs on threshold, recipient and clock: “real risk of significant harm” to the OPC versus 72 hours to a supervisory authority for anything above a low-risk floor.
  • Quebec Law 25 is the strictest Canadian regime and imposes its own assessment before sending information outside Quebec.
  • Federal reform stalled: Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025, and as of 30 July 2026 no successor has been enacted.

Two Different Architectures

PIPEDA (S.C. 2000, c. 5) carries its substantive rules in Schedule 1, which reproduces the ten fair information principles of the CSA Model Code: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Over the top sits s. 5(3), the reasonableness override — an organisation may collect, use or disclose personal information only for purposes that “a reasonable person would consider are appropriate in the circumstances”.

That is a standards-based statute. Much of it is drafted with “should” rather than “shall”, and its meaning has been filled in by OPC findings and Federal Court decisions rather than by the text.

The GDPR does the opposite. It states principles in Art. 5, then makes each one operational through specific articles: lawful basis in Art. 6, information duties in Arts. 13-14, rights in Arts. 15-22, security in Art. 32, records in Art. 30, impact assessments in Art. 35. Where PIPEDA says “be accountable”, the GDPR says which document proves it.

The lawful basis gap. PIPEDA runs on consent plus a list of statutory exceptions in ss. 7, 7.2 and 7.3 (business transactions, employment relationships, investigations, publicly available information). It has no general balancing basis. The GDPR has six bases, including legitimate interests under Art. 6(1)(f), which requires a documented three-part test. Canadian companies frequently arrive with neither: no consent record good enough for Art. 7, and no legitimate interests assessment because they never had to write one.

PIPEDA requires meaningful consent, elaborated in the OPC’s guidelines that took effect on 1 January 2019. Consent may be express or implied, and the form scales with sensitivity: express consent for sensitive information, implied consent acceptable for non-sensitive information where the use is obvious to a reasonable person. Consent can be a condition of service where the information is required for a legitimate purpose.

The GDPR’s Art. 4(11) definition is narrower — freely given, specific, informed and unambiguous, given by a statement or clear affirmative action. Art. 7(3) requires withdrawal to be as easy as giving it, and Art. 7(4) makes consent presumptively invalid where it is bundled into a contract that does not need it. There is no implied consent in the GDPR sense. For health data, Art. 9(2)(a) demands explicit consent, a higher standard still. Our page on Art. 7 sets out what a defensible consent record has to contain.

Practical consequence: a Canadian consent banner and privacy statement that satisfy the OPC will typically fail on granularity, on the absence of a withdrawal mechanism of equal ease, and on pre-ticked or bundled options.

Rights

Right PIPEDA GDPR
Access Principle 9; 30 days, extendable Art. 15; one month, extendable by two
Correction Principle 4.9.5 Art. 16
Erasure No general right Art. 17
Portability No Art. 20
Objection No general right Art. 21
Restriction No Art. 18
Automated decisions No general right Art. 22
Withdraw consent Yes, subject to legal or contractual restrictions Art. 7(3)

The absent rows are the work. Building a right to erasure workflow means knowing every system holding a copy, including backups and processors, and being able to demonstrate deletion. A portability response means structured, commonly used, machine-readable output. Neither exists as a habit in a PIPEDA-only organisation.

Breach Reporting

PIPEDA’s s. 10.1, in force since 1 November 2018, requires an organisation to report to the Privacy Commissioner as soon as feasible a breach of security safeguards that creates a real risk of significant harm to an individual, to notify affected individuals, and under s. 10.3 to keep a record of every breach for 24 months regardless of whether it was reportable.

The GDPR’s Art. 33 requires notification to the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to rights and freedoms — a materially lower threshold than “real risk of significant harm”, so more incidents are notifiable. Art. 34 adds communication to individuals where the risk is high. Our 72-hour notification guide covers running the clock in practice.

A Canadian company with EU exposure therefore runs at least two clocks over one incident, and three if Quebec is involved. That is a process design problem, not a legal one.

Enforcement: the widest gap

The OPC is an ombudsman. It investigates, issues findings and makes recommendations; it has no order-making power and no authority to impose administrative monetary penalties under PIPEDA. Escalation runs through an application to the Federal Court under s. 14, which may award damages. PIPEDA’s offence provisions cap fines at CAD 100,000, and they attach to narrow conduct such as obstructing an investigation or failing to keep breach records.

The GDPR’s Art. 83 provides for administrative fines of up to EUR 10 million or 2% of worldwide turnover for the lower tier and EUR 20 million or 4% for the higher, imposed directly by a supervisory authority, with detailed criteria for calculation. Art. 82 adds a compensation right against controllers and processors.

Quebec Law 25 Is the Stricter Regime

The Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25), assented on 22 September 2021, phased in over three years: governance, a mandated privacy officer and confidentiality-incident reporting from 22 September 2022; the substantive obligations from 22 September 2023; portability from 22 September 2024.

Law 25 closes several of the PIPEDA gaps in the GDPR’s direction. Express consent for sensitive information. Privacy by default for technological products and services offered to the public. A right to de-indexing. Transparency about automated decision-making with a right to submit observations. Privacy impact assessments for information system projects. Portability. A private right of action with punitive damages of at least CAD 1,000 for unlawful infringement. And administrative monetary penalties of up to CAD 10 million or 2% of worldwide turnover, with penal fines up to CAD 25 million or 4%.

The transfer duty is the one Canadian companies miss. Before communicating personal information outside Quebec, an organisation must conduct an assessment of whether the information will receive adequate protection, having regard in particular to generally recognised principles of personal information protection, and the communication must be the subject of a written agreement. That is a Quebec-side obligation running in the opposite direction to the GDPR’s Chapter V, and it applies to a Montreal company sending data to a US cloud provider just as the GDPR applies to a Paris client sending data to Montreal. Our page on Canada-EU data transfers handles the inbound leg.

Alberta and British Columbia also operate private-sector statutes designated substantially similar to PIPEDA, and Alberta’s PIPA has required breach reporting to its Commissioner since 2010.

Federal Reform: Where It Stands

Bill C-27, the Digital Charter Implementation Act, 2022, would have replaced Part 1 of PIPEDA with the Consumer Privacy Protection Act, created a Personal Information and Data Protection Tribunal, and enacted the Artificial Intelligence and Data Act. It reached committee stage and then died on the Order Paper when Parliament was prorogued on 6 January 2025.

As of 30 July 2026, PIPEDA remains the federal private-sector statute in force and no successor has been enacted. Reform is expected and AI regulation is now expected to proceed on a separate track, but nothing has commenced. Verify the current status before relying on this paragraph — it is the fastest-moving fact on this page.

What This Means Operationally

If the GDPR applies to your Canadian company, budget for what PIPEDA never required: an Art. 30 record of processing activities, documented lawful bases including Art. 9 conditions for health data, a DPIA process, Art. 28 contracts with every processor, an Art. 27 EU representative unless you have an EU establishment, erasure and portability workflows, and a 72-hour breach chain. Our comparison of GDPR compliance software for Canadian companies looks at which of these a platform can genuinely carry, and the wider question of whether the GDPR applies outside the EU sets the scope test.

FAQ

Does PIPEDA compliance make us GDPR compliant?

No. The overlap is real on transparency, access and safeguards, but PIPEDA has no records obligation, no erasure or portability rights, no DPIA regime, no EU representative requirement and a different breach standard. Expect a genuine project, not a mapping exercise.

Is PIPEDA “equivalent” to the GDPR because Canada is adequate?

No. Adequacy means the Commission judged the protection given to transferred data to be essentially equivalent for that purpose. It is a finding about a data flow, not a declaration that the statutes match, and the Canadian decision is limited to organisations subject to PIPEDA.

Which applies if we are in Quebec and also caught by the GDPR?

Both, cumulatively, plus PIPEDA for interprovincial and international flows. Design to the strictest element of each obligation rather than trying to reconcile them: express consent for sensitive data, GDPR retention discipline, Quebec’s outbound assessment, and the GDPR’s 72-hour clock.

Do we need a DPO?

PIPEDA requires an accountable individual under Principle 1, and Quebec Law 25 designates the person with the highest authority by default unless the role is delegated in writing. The GDPR’s Art. 37 threshold is different and turns on core-activity monitoring or large-scale Art. 9 processing — which most health companies meet. See our guide to DPO designation.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →