Skip to content
Legiscope
Menu
Data Privacy

PIPEDA vs GDPR: What Canadian Businesses Must Know

PIPEDA's ten principles against the GDPR's structure: consent, erasure, breach reporting to the OPC, Quebec Law 25, enforcement powers and the state of federal reform.

PIPEDA and the GDPR are not two versions of the same law. They were built on different premises, they allocate risk differently, and a Canadian company that is compliant with one is measurably short of the other. The gap is not stylistic. It is a set of specific documents, workflows and rights that PIPEDA never asks for.

The European Commission has confirmed that Canada continues to provide an adequate level of protection for data transferred to organisations subject to PIPEDA, most recently in its January 2024 report on the first review of the pre-GDPR adequacy decisions. Adequacy is a finding about the protection given to imported data. It is not a statement that the two laws are equivalent, and no non-EU statute is. If the GDPR applies to you directly — see our analysis of when the GDPR reaches Canadian companies — you comply with the GDPR on its own terms.

Key Takeaways

  • PIPEDA is principles-based with a reasonableness standard; the GDPR is rule-based with six enumerated lawful bases.
  • PIPEDA has no general right to erasure, no portability right and no ROPA obligation.
  • Breach reporting differs on threshold, recipient and clock: “real risk of significant harm” to the OPC versus 72 hours to a supervisory authority for anything above a low-risk floor.
  • Quebec Law 25 is the strictest Canadian regime and imposes its own assessment before sending information outside Quebec.
  • Federal reform stalled: Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025, and as of 30 July 2026 no successor has been enacted.

Two Different Architectures

PIPEDA (S.C. 2000, c. 5) carries its substantive rules in Schedule 1, which reproduces the ten fair information principles of the CSA Model Code: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Over the top sits s. 5(3), the reasonableness override — an organisation may collect, use or disclose personal information only for purposes that “a reasonable person would consider are appropriate in the circumstances”.

That is a standards-based statute. Much of it is drafted with “should” rather than “shall”, and its meaning has been filled in by OPC findings and Federal Court decisions rather than by the text.

The GDPR does the opposite. It states principles in Art. 5, then makes each one operational through specific articles: lawful basis in Art. 6, information duties in Arts. 13-14, rights in Arts. 15-22, security in Art. 32, records in Art. 30, impact assessments in Art. 35. Where PIPEDA says “be accountable”, the GDPR says which document proves it.

The lawful basis gap. PIPEDA runs on consent plus a list of statutory exceptions in ss. 7, 7.2 and 7.3 (business transactions, employment relationships, investigations, publicly available information). It has no general balancing basis. The GDPR has six bases, including legitimate interests under Art. 6(1)(f), which requires a documented three-part test. Canadian companies frequently arrive with neither: no consent record good enough for Art. 7, and no legitimate interests assessment because they never had to write one.

PIPEDA requires meaningful consent, elaborated in the OPC’s guidelines that took effect on 1 January 2019. Consent may be express or implied, and the form scales with sensitivity: express consent for sensitive information, implied consent acceptable for non-sensitive information where the use is obvious to a reasonable person. Consent can be a condition of service where the information is required for a legitimate purpose.

The GDPR’s Art. 4(11) definition is narrower — freely given, specific, informed and unambiguous, given by a statement or clear affirmative action. Art. 7(3) requires withdrawal to be as easy as giving it, and Art. 7(4) makes consent presumptively invalid where it is bundled into a contract that does not need it. There is no implied consent in the GDPR sense. For health data, Art. 9(2)(a) demands explicit consent, a higher standard still. Our page on Art. 7 sets out what a defensible consent record has to contain.

Practical consequence: a Canadian consent banner and privacy statement that satisfy the OPC will typically fail on granularity, on the absence of a withdrawal mechanism of equal ease, and on pre-ticked or bundled options.

Rights

Right PIPEDA GDPR
Access Principle 9; 30 days, extendable Art. 15; one month, extendable by two
Correction Principle 4.9.5 Art. 16
Erasure No general right Art. 17
Portability No Art. 20
Objection No general right Art. 21
Restriction No Art. 18
Automated decisions No general right Art. 22
Withdraw consent Yes, subject to legal or contractual restrictions Art. 7(3)

The absent rows are the work. Building a right to erasure workflow means knowing every system holding a copy, including backups and processors, and being able to demonstrate deletion. A portability response means structured, commonly used, machine-readable output. Neither exists as a habit in a PIPEDA-only organisation.

Breach Reporting

PIPEDA’s s. 10.1, in force since 1 November 2018, requires an organisation to report to the Privacy Commissioner as soon as feasible a breach of security safeguards that creates a real risk of significant harm to an individual, to notify affected individuals, and under s. 10.3 to keep a record of every breach for 24 months regardless of whether it was reportable.

The GDPR’s Art. 33 requires notification to the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to rights and freedoms — a materially lower threshold than “real risk of significant harm”, so more incidents are notifiable. Art. 34 adds communication to individuals where the risk is high. Our 72-hour notification guide covers running the clock in practice.

A Canadian company with EU exposure therefore runs at least two clocks over one incident, and three if Quebec is involved. That is a process design problem, not a legal one.

Enforcement: the widest gap

The OPC is an ombudsman. It investigates, issues findings and makes recommendations; it has no order-making power and no authority to impose administrative monetary penalties under PIPEDA. Escalation runs through an application to the Federal Court under s. 14, which may award damages. PIPEDA’s offence provisions cap fines at CAD 100,000, and they attach to narrow conduct such as obstructing an investigation or failing to keep breach records.

The GDPR’s Art. 83 provides for administrative fines of up to EUR 10 million or 2% of worldwide turnover for the lower tier and EUR 20 million or 4% for the higher, imposed directly by a supervisory authority, with detailed criteria for calculation. Art. 82 adds a compensation right against controllers and processors.

Quebec Law 25 Is the Stricter Regime

The Act to modernize legislative provisions as regards the protection of personal information (SQ 2021, c. 25), assented on 22 September 2021, phased in over three years: governance, a mandated privacy officer and confidentiality-incident reporting from 22 September 2022; the substantive obligations from 22 September 2023; portability from 22 September 2024.

Law 25 closes several of the PIPEDA gaps in the GDPR’s direction. Express consent for sensitive information. Privacy by default for technological products and services offered to the public. A right to de-indexing. Transparency about automated decision-making with a right to submit observations. Privacy impact assessments for information system projects. Portability. A private right of action with punitive damages of at least CAD 1,000 for unlawful infringement. And administrative monetary penalties of up to CAD 10 million or 2% of worldwide turnover, with penal fines up to CAD 25 million or 4%.

The transfer duty is the one Canadian companies miss. Before communicating personal information outside Quebec, an organisation must conduct an assessment of whether the information will receive adequate protection, having regard in particular to generally recognised principles of personal information protection, and the communication must be the subject of a written agreement. That is a Quebec-side obligation running in the opposite direction to the GDPR’s Chapter V, and it applies to a Montreal company sending data to a US cloud provider just as the GDPR applies to a Paris client sending data to Montreal. Our page on Canada-EU data transfers handles the inbound leg.

Alberta and British Columbia also operate private-sector statutes designated substantially similar to PIPEDA, and Alberta’s PIPA has required breach reporting to its Commissioner since 2010.

Federal Reform: Where It Stands

Bill C-27, the Digital Charter Implementation Act, 2022, would have replaced Part 1 of PIPEDA with the Consumer Privacy Protection Act, created a Personal Information and Data Protection Tribunal, and enacted the Artificial Intelligence and Data Act. It reached committee stage and then died on the Order Paper when Parliament was prorogued on 6 January 2025.

As of 30 July 2026, PIPEDA remains the federal private-sector statute in force and no successor has been enacted. Reform is expected and AI regulation is now expected to proceed on a separate track, but nothing has commenced. Verify the current status before relying on this paragraph — it is the fastest-moving fact on this page.

What This Means Operationally

If the GDPR applies to your Canadian company, budget for what PIPEDA never required: an Art. 30 record of processing activities, documented lawful bases including Art. 9 conditions for health data, a DPIA process, Art. 28 contracts with every processor, an Art. 27 EU representative unless you have an EU establishment, erasure and portability workflows, and a 72-hour breach chain. Our comparison of GDPR compliance software for Canadian companies looks at which of these a platform can genuinely carry, and the wider question of whether the GDPR applies outside the EU sets the scope test.

FAQ

Does PIPEDA compliance make us GDPR compliant?

No. The overlap is real on transparency, access and safeguards, but PIPEDA has no records obligation, no erasure or portability rights, no DPIA regime, no EU representative requirement and a different breach standard. Expect a genuine project, not a mapping exercise.

Is PIPEDA “equivalent” to the GDPR because Canada is adequate?

No. Adequacy means the Commission judged the protection given to transferred data to be essentially equivalent for that purpose. It is a finding about a data flow, not a declaration that the statutes match, and the Canadian decision is limited to organisations subject to PIPEDA.

Which applies if we are in Quebec and also caught by the GDPR?

Both, cumulatively, plus PIPEDA for interprovincial and international flows. Design to the strictest element of each obligation rather than trying to reconcile them: express consent for sensitive data, GDPR retention discipline, Quebec’s outbound assessment, and the GDPR’s 72-hour clock.

Do we need a DPO?

PIPEDA requires an accountable individual under Principle 1, and Quebec Law 25 designates the person with the highest authority by default unless the role is delegated in writing. The GDPR’s Art. 37 threshold is different and turns on core-activity monitoring or large-scale Art. 9 processing — which most health companies meet. See our guide to DPO designation.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

GDPR Compliance Software for Canadian Companies (2026)

The harder question is what a Canadian buyer needs that a generic GDPR tool does not give them. That is what this guide covers.

July 30, 2026
02Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
03Data Privacy

DSAR Software Compared: Automate Subject Requests

Get identity verification wrong and the tool becomes a liability: the Dutch DPA fined DPG Media EUR 525,000 in 2020 for demanding a copy of an ID document to process access requests. The software you…

July 6, 2026
04Data Privacy

FADP vs GDPR: Breach Notification, Sanctions, Authorities

In one sentence. The revised Swiss FADP (nFADP) in force since 1 September 2023 and the GDPR in force since 25 May 2018 share most concepts but diverge on three operational points: (1) breach…

June 3, 2026
05Data Privacy

GDPR Audit Checklist + Best Audit Tools 2026

A GDPR audit checklist is a structured, section-by-section list of what you must be able to evidence under the GDPR: your lawful bases, your record of processing activities, your processor contracts,…

July 8, 2026
06Data Privacy

ROPA Software: Automate Article 30 Records (2026)

The ROPA is not paperwork for its own sake. It is the first document every DPA requests when an inspection or complaint lands, and an incomplete one is itself evidence of an Art. 30 breach.

July 7, 2026
07Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
08Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026