Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Canada has one federal private sector privacy law, three substantially similar provincial ones, a set of provincial health statutes, and separate public sector regimes. Most companies are subject to more than one. Here is how to work out which.
Start with three questions: where are the individuals whose information you hold, what kind of information is it, and who is your customer. PIPEDA is the federal default for personal information handled in the course of commercial activity, and it also governs interprovincial and international flows. Quebec, Alberta and British Columbia each have their own private sector statute that displaces PIPEDA for activity wholly inside that province. Health information held by health care providers is carved out into provincial statutes: PHIPA in Ontario, the Health Information Act in Alberta, and equivalents elsewhere. Selling to government brings you into the orbit of public sector statutes through your customer, not directly. Almost every Canadian company of any size is subject to PIPEDA plus at least one other regime, and the operational answer is one control set that satisfies the strictest applicable requirement.
Canada does not have one privacy law. It has a federal statute for the private sector, a federal statute for federal government institutions, general private sector statutes in three provinces, health-specific statutes in most provinces, public sector statutes in every province, and a scattering of sector rules on top. The structure is a product of the constitutional division of powers, not of design, and it means the correct answer to "which law applies to us" is usually "several".
The federal private sector law is the Personal Information Protection and Electronic Documents Act, PIPEDA. It applies to organizations that collect, use or disclose personal information in the course of commercial activity, and to federal works, undertakings and businesses such as banks, airlines, railways and telecommunications carriers, including their employee information.
PIPEDA yields to provincial law in a specific way. Where a province has enacted a private sector privacy law that the federal government has declared substantially similar to PIPEDA, organizations in that province are exempt from PIPEDA in respect of the collection, use and disclosure of personal information that occurs within that province. Quebec, Alberta and British Columbia have such laws. Ontario, and the rest of Canada, do not have a general private sector statute, so PIPEDA applies directly there.
The word "within" is doing a lot of work. PIPEDA continues to apply to personal information that crosses a provincial or a national border in the course of commercial activity, regardless of the province of origin. A Vancouver company serving customers in Ontario is subject to BC PIPA for its internal, provincial activity and to PIPEDA for the interprovincial flow. In practice most companies of any size are subject to both a provincial statute and PIPEDA at once, which is why the operational answer is a single program built to the strictest requirement rather than a matrix of separate ones.
Health information is the other major carve-out. Several provinces have health-specific statutes that have been declared substantially similar in respect of health information custodians, which pulls that information out of PIPEDA within those provinces. Ontario's PHIPA is the most consequential of these for technology companies, and Alberta's Health Information Act is the other one with a distinctive structure.
Work through these in order. Each question narrows the set, and the honest end state for most companies is a list rather than a single statute.
Are you handling personal information in the course of commercial activity? If yes, a private sector regime applies. If you are a not-for-profit, a charity, a political party or an association, the answer is more complicated: PIPEDA reaches non-commercial organizations only in limited ways, but Alberta and BC PIPA apply to non-profits in respect of some activities, and Quebec's law applies to any person carrying on an enterprise. Do not assume non-profit status is an exemption.
Are you a federal work, undertaking or business? Banks, airlines, railways, marine and interprovincial trucking, broadcasters and telecommunications carriers are federally regulated. PIPEDA applies to them including their employee personal information, and provincial private sector law does not displace it. If you supply one of these, you are not federally regulated yourself, but their obligations flow into your contract.
Where does the activity take place? Personal information collected, used and disclosed wholly within Quebec, Alberta or British Columbia falls under that province's statute. Everything crossing a provincial or national border in commercial activity keeps PIPEDA in play. Ontario, Manitoba, Saskatchewan, Atlantic Canada and the territories have no general private sector statute, so PIPEDA governs directly.
Is any of it health information held for a health care provider? If you handle personal health information on behalf of custodians, the provincial health statute governs that information in that province. This is a status question, not a data-type question: the same blood pressure reading is health information under PHIPA when held for an Ontario clinic and ordinary personal information under PIPEDA when a consumer types it into your direct-to-consumer app.
Is your customer a public body? Selling to a provincial ministry, a municipality, a school board, a university or a federal institution does not make you subject to their statute, but it makes their obligations your contract terms. Ontario institutions are working through the Bill 194 changes right now, BC and Alberta public bodies have their own assessment requirements, and federal institutions operate under the Privacy Act and Treasury Board direction.
Do you have European, UK or other foreign individuals? If so add the GDPR or its equivalents to the list. Our PIPEDA versus GDPR comparison covers where the two diverge, and the short version is that GDPR is more prescriptive on lawful basis, records of processing and transfer mechanics, while PIPEDA is more open-textured and more reliant on reasonableness.
Our privacy law finder runs this logic interactively if you would rather answer questions than read them.
PIPEDA is principles-based. Its substantive requirements sit in ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. On top of the principles sits an overriding reasonableness test: an organization may collect, use or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.
Operationally, PIPEDA compliance for a technology company means the following. A designated individual accountable for privacy, named. A privacy policy that states purposes in specific terms rather than in categories. Consent that is meaningful, which the Privacy Commissioner has interpreted to require that key elements be highlighted rather than buried, with express consent for sensitive information. A retention schedule with actual periods. Security safeguards proportionate to sensitivity. A process for access requests, with a thirty-day response clock. And a breach regime.
The breach obligations are the most concrete part of PIPEDA and the part most often unimplemented. An organization must report to the Privacy Commissioner of Canada, and notify affected individuals, any breach of security safeguards involving personal information under its control where it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual. Significant harm is defined broadly and includes humiliation, damage to reputation or relationships, loss of employment or business opportunity, financial loss, identity theft, and negative effects on a credit record. Report and notification must happen as soon as feasible.
Separately, and this is the requirement people forget, an organization must maintain a record of every breach of security safeguards involving personal information under its control, regardless of whether it met the reporting threshold, and must provide those records to the Commissioner on request. The record has to contain enough information to let the Commissioner verify the organization's risk assessment. Practically that means a breach log with date, description, information involved, individuals affected, the harm assessment and its reasoning, and the decision. Twenty-four months is the retention period specified in the regulations.
PIPEDA has no administrative monetary penalty regime. Enforcement runs through Commissioner investigations, findings and reports, compliance agreements, and Federal Court applications, with offence provisions attached mainly to obstructing an investigation, destroying records and failing to keep breach records. Reform has been on the legislative agenda for several years without passing, so the safe planning assumption is that PIPEDA stays as it is while provincial law gets stricter.
Quebec's Law 25 amended the province's private sector privacy act in stages between 2022 and 2024, and the result is the most demanding general privacy regime in the country. If you serve Quebec residents, build to Law 25 and the rest of Canada follows for free.
The distinctive requirements are these. A privacy officer, whose title and contact details must be published; by default the role sits with the person with the highest authority in the enterprise unless delegated in writing. Confidentiality incident obligations: keep a register of incidents, and where an incident presents a risk of serious injury, notify the Commission d'accès à l'information and affected individuals promptly. A privacy impact assessment requirement for any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information. Privacy by default for technological products and services offered to the public, meaning the highest level of confidentiality without any action by the user. Transparency and a right to object where a decision is based exclusively on automated processing. Data portability, in force since September 2024, giving individuals the right to receive computerized personal information they provided in a structured, commonly used technological format.
The cross-border rule is the one that changes architecture decisions. Before communicating personal information outside Quebec, an enterprise must conduct an assessment of the privacy-related factors, considering the sensitivity of the information, the purposes for which it will be used, the protection measures including contractual ones, and the legal framework applicable in the destination jurisdiction. The information may be communicated only if the assessment establishes that it would receive adequate protection, in particular in light of generally recognized privacy principles, and the communication must be the subject of a written agreement that takes the assessment results into account.
Note what this is and is not. It is not a residency requirement. Quebec does not say personal information must stay in Quebec or in Canada. It says you must assess, conclude adequacy, and paper the transfer. In practice, for the large cloud providers, the assessment is a document rather than an obstacle, and the work is doing it and keeping it current rather than changing where you host. Our data residency guide takes this apart in detail.
Enforcement has real teeth. Law 25 introduced administrative monetary penalties of up to $10 million or 2 percent of worldwide turnover, whichever is greater, and penal fines of up to $25 million or 4 percent of worldwide turnover for offences. It also created a private right of action with punitive damages of at least $1,000 for unlawful infringement of a right conferred by the Act. That combination is why Quebec is the jurisdiction that changes behaviour. Our guide on what Law 25 requires and the checklist go through implementation.
Alberta and British Columbia each have a Personal Information Protection Act. They are similar to each other and to PIPEDA in structure, and both were declared substantially similar, so they displace PIPEDA for intra-provincial commercial activity in their provinces.
The most significant practical difference from PIPEDA is that both cover employee personal information in the private sector, which PIPEDA does not do outside federally regulated businesses. Both provide a route to collect, use and disclose personal employee information without consent where it is reasonable for the purposes of establishing, managing or terminating the employment relationship, subject to giving notice. If you have staff in Alberta or BC, your HR data handling is regulated in a way it would not be in Ontario.
Alberta PIPA has a mandatory breach regime that predates PIPEDA's. An organization must notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay of any incident involving the loss of or unauthorized access to or disclosure of personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual. Distinctively, the Alberta Commissioner then decides whether individuals must be notified and can direct the organization to do so. That is a different mechanic from PIPEDA, where the organization makes the notification decision itself.
British Columbia is the exception on breaches. PIPA carries no statutory notification duty at all, which makes BC the only jurisdiction in Canada where a private sector organization is not required to report a breach to anyone. The Commissioner publishes guidance urging notification and provides the forms, and customer contracts almost always require it, but the statute does not. The mandatory regime in the province sits in FIPPA and binds public bodies. BC also has a distinctive history on data residency, covered below and in our Alberta HIA and BC PIPA guide.
Neither statute has Quebec-scale monetary penalties, and both are enforced primarily through Commissioner investigations and orders. What both Commissioners do have is order-making power, which PIPEDA's federal Commissioner lacks. An Alberta or BC order is binding and directs you to do or stop doing something specific.
Health information gets its own statutes because the provinces regulate the delivery of health care. The pattern is consistent: a defined class of custodian or trustee holds the information, the statute binds that class directly, and vendors reach the statute through the custodian.
Ontario's PHIPA is the one most technology companies meet first, because Ontario has the largest health system and the most active health technology sector. It works through custodians and their agents, adds direct duties for electronic service providers and health information network providers, and is enforced by the Information and Privacy Commissioner of Ontario. We cover it in depth in the PHIPA guide.
Alberta's Health Information Act uses different vocabulary: custodians, affiliates rather than agents, and information managers, the last being the category most software vendors occupy, with a required information manager agreement. Alberta also has a distinctive requirement to submit privacy impact assessments to the Commissioner before implementing new practices or systems, which is a submission rather than an internal document.
Other provinces follow the same shape with local names: Saskatchewan and Manitoba have Health Information Protection Acts with trustees, New Brunswick, Nova Scotia, Newfoundland and Labrador and Prince Edward Island each have personal health information legislation, and British Columbia handles health information mostly through its public sector statute for public bodies plus PIPA for private providers rather than through a dedicated private health act. If you are selling nationally, the practical approach is to build to the strictest of Ontario and Alberta and then check the local variations on breach notification and assessment submission.
The mistake to avoid is assuming that because you handle health data you are automatically under a health statute. The statutes attach to custodians. A direct-to-consumer wellness app with no custodian relationship is a PIPEDA or provincial private sector matter, with all the same sensitivity but a different legal frame, a different regulator and a different breach threshold.
The federal Privacy Act governs personal information held by federal government institutions. Provincial statutes govern their own public bodies: FIPPA and MFIPPA in Ontario, FIPPA in British Columbia, and in Alberta the access and privacy legislation for public bodies that replaced the long-standing FOIP Act. Quebec has a public sector act alongside its private sector one.
None of these bind you as a supplier. All of them reach you through the contract, because a public body has to be able to demonstrate that information in its custody or control is handled lawfully even when it lives in a vendor's system.
The recurring flow-downs are: a privacy impact assessment that you must supply the facts for, a security threat and risk assessment, restrictions on where information may be stored or accessed from, obligations to cooperate with access-to-information requests because the records may be in the institution's custody or control, breach notification clauses with clocks set by the institution's own duty, audit rights, and return or destruction of information at the end of the contract.
Ontario's Bill 194 has added an information security duty, mandatory privacy impact assessments and breach notification to the Commissioner on the provincial side, which is why Ontario public sector procurement has become noticeably heavier. Our guides on Bill 194 and on selling to the Canadian public sector cover the artifacts you need.
Overlap is the normal case, not the exception. A Toronto-based SaaS company with customers across Canada, staff in Vancouver, one hospital customer in Ontario and a handful of Quebec accounts is subject to PIPEDA, BC PIPA for its employee data, Quebec's private sector act, and PHIPA through its custodian customer. That is four regimes for one company of thirty people.
Do not build four programs. Build one, to the strictest applicable standard on each dimension, and document which requirement each control is answering. The strictest standard varies by dimension, which is why a blanket "we follow GDPR" is not a strategy: GDPR is stricter on lawful basis and transfer mechanics, Quebec is stricter on privacy by default and automated decision transparency, Alberta is distinctive on breach notification mechanics, PIPEDA is distinctive on breach record-keeping, and the health statutes are stricter on audit logging and consent directives than any general privacy law.
A practical way to run this is a requirements register: one row per obligation, columns for each statute that imposes something like it, the strictest formulation, the control that satisfies it, the evidence, and the owner. It looks like extra work for about two weeks and then it answers every questionnaire and every regulator letter for years.
The second practical device is a single incident procedure with a decision tree at the top. When something happens, the questions are: whose information, in which province, held in what capacity, and which regulators and customers have to be told, in what order, on what clock. Working that out during an incident is how organizations miss statutory deadlines. Working it out in advance takes an afternoon.
The third is a data map that records, for every store, the categories of information, the provinces of the individuals, the capacity in which you hold it, the retention period and the subprocessors. Almost every question in this guide is answerable in minutes if that map exists and unanswerable in weeks if it does not.
It is worth being concrete about which statute causes which piece of work, because the differences are smaller than the marketing around them suggests and they concentrate in a few places.
PIPEDA adds: a named accountable individual, meaningful consent in your product flows, a real risk of significant harm assessment process, reporting to the Privacy Commissioner of Canada, and a breach register kept for twenty-four months even for incidents you did not report.
Quebec Law 25 adds: a published privacy officer, a confidentiality incident register, mandatory impact assessments for system projects and for out-of-province communications, privacy by default in product settings, automated decision disclosure and a right to submit observations, data portability, and materially higher penalty exposure.
Alberta and BC PIPA add: employee personal information within scope, notice-based handling for the employment relationship, and in Alberta a breach notification path where the Commissioner decides on individual notification.
Health statutes add: record-level audit logging that can answer who viewed a named individual's record, consent directives and the ability to represent and honour them, retention driven by professional record-keeping rules that run to a decade, custodian notification clocks measured in hours, and in Ontario the health information network provider duties including a written assessment every two years.
Public sector contracts add: privacy impact assessment input, threat and risk assessments, access-to-information cooperation, residency commitments, and return or certified destruction at contract end.
Everything else, and it is most of the total effort, is the same in every regime: know what you hold, limit who can reach it, protect it proportionately, keep it only as long as you need it, be able to prove all of the above, and have a plan for when it goes wrong.
Privacy statutes and security frameworks answer different questions and buyers routinely conflate them. A statute tells you what you may do with information and what rights individuals have. A framework such as SOC 2 or ISO 27001 gives you a structure for demonstrating that your controls exist and operate.
Neither substitutes for the other. A SOC 2 Type II report says nothing about whether your consent language is meaningful or whether you have a privacy officer. A perfect privacy policy says nothing about whether your production database is encrypted. But the overlap on the safeguards dimension is large, which is why a single control set is efficient.
The efficient sequence for a Canadian company is usually: establish which statutes apply and write down the obligations, build the data map and the retention schedule, fix access control and logging, then wrap a framework around it if a buyer requires one. Doing it in the other order produces a certified organization that cannot answer a subject access request.
One caution on ISO 27701 and similar privacy extensions: they are useful structuring tools and they are not evidence of compliance with any Canadian statute. No Canadian regulator recognizes a certification as compliance. What certifications buy you is credibility with buyers, and that is worth having, but say it accurately.
Assuming one law applies. Most Canadian companies are subject to PIPEDA plus at least one provincial regime, and the one you forget is the one with the different clock.
Assuming Quebec means residency. Law 25 requires an assessment and a written agreement for out-of-province communication, not Quebec-only storage. Companies have re-architected unnecessarily on this misunderstanding.
Missing the PIPEDA breach register. The obligation to record every breach of security safeguards, including ones below the reporting threshold, is easy to comply with and commonly ignored. It is also one of the few things carrying an offence provision.
Treating employee data as out of scope. True under PIPEDA for provincially regulated businesses, false in Alberta and BC, and false for federally regulated employers.
Applying health-grade controls to the wrong data. The status of the information matters more than its content. Know in which capacity you hold each store.
Consent as a checkbox. Meaningful consent under PIPEDA and Quebec law requires that key elements be surfaced, that purposes be specific, and that sensitive information get express consent. Bundled acceptance of a twelve-page policy does not meet the standard anywhere in Canada.
No incident decision tree. Statutory clocks run from the moment you know, not from the moment you finish investigating. Deciding who to tell during the incident is how deadlines get missed.
| Statute | Who it covers | Distinctive obligations |
|---|---|---|
| PIPEDA (federal) | Commercial activity across Canada, all interprovincial and international flows, and federally regulated businesses including their employee information. | Ten fair information principles, meaningful consent, real risk of significant harm breach reporting to the Privacy Commissioner of Canada, and a register of every breach kept for twenty-four months. |
| Quebec private sector act, as amended by Law 25 | Any person carrying on an enterprise in Quebec, in respect of activity within the province. | Published privacy officer, incident register, impact assessments for system projects and out-of-province communication, privacy by default, automated decision transparency, portability, penalties up to 4 percent of worldwide turnover. |
| Alberta PIPA | Organizations in Alberta, including non-profits for some activities, and private sector employee personal information. | Employee information regime with notice, and breach notification to the Alberta Commissioner who then decides on notification to individuals. |
| British Columbia PIPA | Organizations in British Columbia, including employee personal information. | Employee information regime with notice, an order-making Commissioner, and no statutory breach notification duty, which is unique in Canada. |
| PHIPA (Ontario) | Health information custodians in Ontario, their agents, electronic service providers and health information network providers. | Record-level audit logging, consent directives, custodian notification at the first reasonable opportunity, and a written assessment every two years for network providers. |
| Alberta Health Information Act | Custodians in Alberta, their affiliates, and information managers acting for them. | Information manager agreement, privacy impact assessments submitted to the Alberta Commissioner before implementation, and its own breach notification duties. |
| Public sector statutes | Federal institutions under the Privacy Act, and provincial and municipal bodies under their own access and privacy legislation. | Reach vendors through contract: privacy impact assessment input, threat and risk assessments, residency terms, access-to-information cooperation, and return or destruction at contract end. |
Yes. Ontario has no general private sector privacy statute, so PIPEDA applies directly to personal information you handle in the course of commercial activity. The exception is personal health information held by health information custodians, which PHIPA governs instead. If your customers or your data cross provincial or national borders, PIPEDA applies to those flows in any event, including for companies based in Quebec, Alberta or British Columbia.
Close, but not automatically. Law 25 is the strictest general regime in the country, so building to it covers most of PIPEDA, Alberta PIPA and BC PIPA. What it does not cover is the health statutes, which impose requirements no general privacy law contains, such as record-level audit logging and consent directives, and it does not cover procedural differences like PIPEDA's twenty-four month breach register or Alberta's Commissioner-directed notification. Build to Law 25, then check the deltas.
Alberta PIPA and BC PIPA cover employee personal information in the private sector, with a route to collect, use and disclose it without consent for purposes reasonably required to establish, manage or terminate the employment relationship, subject to notice. PIPEDA covers employee information only for federal works, undertakings and businesses such as banks, airlines and telecommunications carriers. Quebec's private sector act applies to personal information held by an enterprise, which includes employee information. Ontario has no general private sector employee privacy statute.
No general Canadian privacy law requires it. PIPEDA permits transfers for processing subject to the accountability principle and contractual protection. Quebec Law 25 requires an assessment of privacy-related factors and a written agreement before communicating personal information outside Quebec, and permits the communication where the assessment establishes adequate protection. Residency requirements that do exist come from specific public sector legislation, government policy and procurement templates rather than from the general private sector statutes.
PHIPA applies to personal health information held by health information custodians in Ontario and by the agents and service providers acting for them. PIPEDA applies to personal information handled in commercial activity generally. The distinguishing question is capacity, not content. The same health data is under PHIPA when you hold it for an Ontario clinic and under PIPEDA when an individual gives it to you directly through a consumer product with no custodian involved. Companies that do both need to know which store is which.
PIPEDA requires reporting to the Privacy Commissioner of Canada and notification to individuals as soon as feasible after determining that a breach creates a real risk of significant harm. Alberta requires notification to its Commissioner without unreasonable delay where a real risk of significant harm exists, and the Commissioner then decides on individual notification. Quebec requires prompt notification of confidentiality incidents presenting a risk of serious injury. Health statutes and contracts commonly impose much shorter clocks, sometimes measured in hours, for notifying a custodian or an institutional customer.
They can. The Privacy Commissioner of Canada has taken the position, upheld in litigation, that PIPEDA applies to foreign organizations with a real and substantial connection to Canada, such as those targeting Canadian individuals or handling their information. Quebec's law applies to enterprises carrying on activity in Quebec. As a practical matter, if you market to Canadians, contract with Canadian customers or process the information of individuals in Canada, plan on Canadian law applying rather than hoping it does not.
Build the data map first: every store, the categories of personal information in it, the provinces of the individuals, the capacity in which you hold it, the retention period and the subprocessors that can reach it. Then write the retention schedule, name an accountable person, fix access control and logging, and write one incident procedure with a decision tree for which regulators and customers get told on what clock. Those five things answer the majority of what any Canadian statute or buyer questionnaire will ask.
traztech Workspace has every control of whichever frameworks apply to you, written in plain English, with somewhere to attach the proof. Free to use, with no card and no trial clock.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
We map the statutes that apply to your data, build one control set that satisfies the strictest of them, and leave you with the evidence a buyer or a regulator would ask for.
Book a strategy callWant the human version?
Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.