PIPEDA Compliance Documentation: A Guide for Canadian Businesses
Canada's privacy landscape spans PIPEDA, Quebec Law 25, and provincial PIPAs. Here's what documentation you need and how to review it systematically.
Canada's privacy landscape is uniquely complex. Federally, the Personal Information Protection and Electronic Documents Act (PIPEDA) governs how private-sector organisations handle personal information. But PIPEDA isn't the only law — Quebec's Law 25 has already introduced GDPR-style requirements with significant penalties, Alberta and British Columbia have their own substantially similar provincial acts (PIPA), and Bill C-27 proposes replacing PIPEDA entirely with the Consumer Privacy Protection Act (CPPA).
For businesses operating across provinces, this means documentation that satisfies multiple privacy regimes simultaneously. The Office of the Privacy Commissioner (OPC) can investigate complaints, conduct audits, and make public findings — and Quebec's Commission d'accès à l'information can now impose fines up to C$25 million or 4% of worldwide turnover.
This guide covers what Canadian privacy documentation you need today, what's changing, and how to build a review process that keeps you compliant across jurisdictions.
The Canadian Privacy Landscape: Multiple Regimes
| Jurisdiction | Law | Regulator | Max Penalty | Key Differences |
|---|---|---|---|---|
| Federal | PIPEDA | OPC | Compliance orders (no fines currently) | 10 fair information principles, complaint-driven enforcement |
| Quebec | Law 25 (modernised privacy law) | CAI | C$25M or 4% of worldwide turnover | Mandatory PIAs, consent reforms, automated decision transparency, private right of action |
| Alberta | PIPA Alberta | OIPC Alberta | C$100,000 per offence | Substantially similar to PIPEDA, covers employees |
| British Columbia | PIPA BC | OIPC BC | C$100,000 per offence | Substantially similar to PIPEDA, covers employees |
| Proposed Federal | CPPA (Bill C-27) | Privacy Tribunal | Up to C$25M or 5% of global revenue | Would replace PIPEDA with stronger enforcement, order-making, and fines |
What This Means for Documentation
A business operating in Ontario serves customers in Quebec and has employees in Alberta. That business potentially needs documentation that satisfies:
- PIPEDA (for customers outside Quebec)
- Law 25 (for Quebec customers and any Quebec-based processing)
- PIPA Alberta (for Alberta employees)
- And soon, potentially the CPPA
The practical approach: build documentation to the highest standard (Quebec Law 25) and it will satisfy all regimes.
PIPEDA's 10 Fair Information Principles
PIPEDA is built on 10 principles, each with documentation implications:
| Principle | Requirement | Documentation Needed |
|---|---|---|
| 1. Accountability | Designate a responsible person; implement policies | Privacy officer designation, privacy management programme, training records |
| 2. Identifying Purposes | Identify purposes before or at collection | Purpose statements, privacy notices at collection points |
| 3. Consent | Knowledge and consent required | Consent mechanisms, consent records, withdrawal processes |
| 4. Limiting Collection | Collect only what's necessary | Data inventory, necessity justifications |
| 5. Limiting Use, Disclosure, Retention | Use only for stated purposes; retain only as needed | Data retention schedules, access controls, disposal records |
| 6. Accuracy | Keep personal information accurate | Data quality procedures, correction processes |
| 7. Safeguards | Protect with appropriate security | Security policies, technical safeguard documentation, breach response plan |
| 8. Openness | Make privacy policies publicly available | Published privacy policy, accessible privacy documentation |
| 9. Individual Access | Individuals can access and challenge their data | Access request procedures, response tracking, correction logs |
| 10. Challenging Compliance | Complaints process available | Complaints procedure, investigation records |
Quebec Law 25: The Highest Standard
Quebec's modernised privacy law sets the bar for Canadian compliance. If your documentation meets Law 25, it meets PIPEDA and the provincial PIPAs.
Key Documentation Requirements Under Law 25
Privacy Impact Assessments (PIAs):
- Mandatory for any project involving personal information
- Must assess privacy risks before the project begins
- Document must cover purpose, necessity, proportionality, and mitigation measures
- Must be conducted for any transfer of personal information outside Quebec
Consent:
- Consent must be clear, free, informed, and given for specific purposes
- Implied consent is restricted — explicit consent required for sensitive information
- Consent for minors under 14 requires parental authorisation
- Documentation of how consent is obtained, managed, and withdrawn
Automated Decision-Making:
- Individuals must be informed when decisions are made exclusively by automated processing
- Must disclose the personal information used, reasons for the decision, and right to have it reviewed by a human
- Documentation of all automated decision systems and their logic
Breach Notification:
- Mandatory notification to the CAI and affected individuals for breaches with a risk of serious injury
- Breach register must be maintained (accessible to CAI on request)
- Breach response plan with clear escalation procedures
Privacy Officer:
- Must designate a person responsible for privacy compliance
- Title and contact information must be published on the organisation's website
- Must be reported to the CAI
Transparency:
- Privacy policy must describe categories of personal information held, purposes, retention periods, and rights
- Must be available in clear, simple language
- Must disclose any third parties to whom data may be communicated
Common Documentation Gaps in Canadian Organisations
1. Privacy Policies Written Under the Old Framework
Many organisations still have privacy policies drafted before Law 25's full implementation. These policies typically:
- Don't address automated decision-making disclosure
- Don't specify data retention periods
- Don't identify the privacy officer by title and contact
- Use vague purpose statements ("to improve our services")
- Don't address cross-border transfer requirements
2. Missing Privacy Impact Assessments
Law 25 made PIAs mandatory, but many organisations:
- Have never conducted a PIA
- Conduct PIAs informally without documentation
- Don't conduct PIAs for existing systems (only new projects)
- Don't conduct PIAs for cross-border transfers
3. Inadequate Breach Documentation
PIPEDA's breach notification has been in effect since 2018, but many organisations:
- Have no documented breach response plan
- Don't maintain a breach register
- Haven't tested their breach response process
- Don't know the difference between PIPEDA and Law 25 breach notification requirements
4. Consent Mechanisms Not Updated
Law 25's stricter consent requirements mean:
- Pre-checked boxes no longer constitute valid consent
- Bundled consent (accept all or nothing) is problematic
- Sensitive information requires explicit consent
- Consent for minors has specific requirements
Many organisations haven't updated their consent mechanisms or documented how consent is obtained.
5. No Data Inventory
You can't protect what you don't know you have. Common gaps:
- No inventory of personal information held
- No mapping of data flows (who collects, who accesses, where it's stored, who it's shared with)
- No documented retention periods by data type
- No record of cross-border transfers
How to Review Your Documentation Systematically
Step 1: Determine Which Laws Apply
Map your operations to the applicable privacy regimes:
- Do you have customers in Quebec? → Law 25 applies
- Do you have employees in Alberta or BC? → Provincial PIPA applies
- Do you operate a federal work, undertaking, or business? → PIPEDA applies
- Do you collect data from individuals in other provinces? → PIPEDA applies
If Law 25 applies, build to that standard for all documentation.
Step 2: Audit Your Privacy Policy
Check your published privacy policy against Law 25 requirements:
- Names or titles of persons responsible for privacy compliance
- Categories of personal information collected
- Purposes for each category of data
- How consent is obtained
- Data retention periods
- Rights of individuals (access, correction, withdrawal of consent, complaint)
- Disclosure of automated decision-making processes
- Cross-border transfer information
- How to contact the privacy officer
- Written in clear, simple language
Step 3: Inventory Personal Information
Create or update a data inventory:
| Data Category | Collection Point | Purpose | Storage | Access | Retention | Cross-border? |
|---|---|---|---|---|---|---|
| Customer names | Registration | Account management | Cloud CRM (US) | Sales, Support | Duration of account + 2 years | Yes — US |
| Employee SINs | HR onboarding | Tax compliance | Payroll system (Canada) | HR, Finance | Employment + 7 years | No |
| Marketing emails | Newsletter signup | Marketing communications | Email platform (US) | Marketing | Until consent withdrawn | Yes — US |
Step 4: Assess PIAs
- Inventory all projects involving personal information
- Verify PIAs exist for each (mandatory under Law 25)
- Check PIAs cover: purpose, necessity, proportionality, risks, mitigations
- Verify PIAs are conducted for cross-border transfers
- Ensure PIAs are documented and accessible
Step 5: Review Breach Response
- Documented breach response plan exists
- Plan covers both PIPEDA and Law 25 notification requirements
- Breach register is maintained
- Notification templates prepared (OPC, CAI, affected individuals)
- Plan has been tested with a tabletop exercise
Using AI to Review Canadian Privacy Documentation
Organisations operating across provinces face a particular documentation challenge: ensuring documentation satisfies multiple privacy regimes simultaneously.
What AI-Assisted Review Can Do
- Multi-regime compliance checking — Does your privacy policy satisfy both PIPEDA and Law 25?
- Completeness screening — Are all Law 25 mandatory elements present?
- Consent mechanism review — Do consent mechanisms meet the stricter Law 25 requirements?
- PIA quality checking — Do PIAs cover all required elements?
- Plain language analysis — Are privacy notices understandable to the average person?
Practical Example: Building a Canadian Privacy Reviewer
In TeamBench, you could configure a reviewer for Canadian privacy documentation:
Reviewer name: Canadian Privacy Compliance Reviewer
System prompt:
You are a Canadian privacy documentation compliance reviewer. Review privacy policies, PIAs, and procedures against both PIPEDA's 10 fair information principles and Quebec Law 25 requirements. Check for completeness, specificity, consent compliance, automated decision-making disclosures, retention periods, cross-border transfer documentation, and plain language accessibility. Flag elements that satisfy PIPEDA but not Law 25. Suggest specific improvements.
Evaluation criteria:
- Law 25 Compliance (weight: 3) — All mandatory Law 25 elements present
- PIPEDA Principles (weight: 3) — All 10 fair information principles addressed
- Specificity (weight: 2) — Tailored to the organisation's actual data practices
- Plain Language (weight: 2) — Written in clear, accessible language
- Cross-border Coverage (weight: 1) — Transfer documentation complete
Quality gate: Minimum score: 75.
Upload PIPEDA, Law 25 provisions, OPC guidance, and your organisation's existing privacy framework into a Knowledge Base. You could also use the readability checker to verify plain language standards.
Frequently Asked Questions
What is PIPEDA and who must comply?
PIPEDA is Canada's federal private-sector privacy law. It applies to organisations that collect, use, or disclose personal information in the course of commercial activity, unless the province has substantially similar legislation (Quebec, Alberta, BC). Even in those provinces, PIPEDA applies to federally regulated industries and cross-border data.
How does Quebec Law 25 differ from PIPEDA?
Law 25 is stricter: it mandates Privacy Impact Assessments, requires explicit consent for sensitive information, requires automated decision-making transparency, imposes fines up to C$25M or 4% of worldwide turnover, and grants a private right of action. PIPEDA currently has no fining power (the OPC has compliance orders only).
What is Bill C-27 and when will it take effect?
Bill C-27 proposes the Consumer Privacy Protection Act (CPPA) to replace PIPEDA, plus the Artificial Intelligence and Data Act (AIDA). It would introduce fines up to C$25M or 5% of global revenue, order-making authority, and a new Privacy Tribunal. Timeline remains uncertain — monitor Parliament for updates.
Do I need a Privacy Impact Assessment?
Under Law 25, yes — PIAs are mandatory for any project involving personal information and for cross-border transfers. Under PIPEDA, PIAs are recommended best practice but not legally mandated. If you operate in or serve Quebec, PIAs are required.
What are the breach notification requirements?
Under PIPEDA, you must report breaches involving a "real risk of significant harm" to the OPC and affected individuals. Under Law 25, you must notify the CAI and affected individuals for breaches with a "risk of serious injury." Both require maintaining a breach register.
How should I handle cross-provincial compliance?
Build documentation to the highest applicable standard (Law 25) and it will satisfy PIPEDA and the provincial PIPAs. Maintain a single, comprehensive privacy programme rather than separate documentation for each regime.
Can AI help with privacy compliance documentation?
AI can assist with first-pass review — checking policies for completeness against both PIPEDA and Law 25, flagging missing elements, identifying outdated provisions, and verifying plain language standards. It cannot provide legal advice, verify implementation, or guarantee regulatory compliance.
How often should privacy documentation be reviewed?
Privacy policies should be reviewed annually and updated when data practices change. PIAs should be conducted for every new project and reviewed annually for existing systems. Breach response plans should be tested annually. Consent mechanisms should be reviewed whenever Law 25 guidance is updated.
Key Takeaways
- Canada's privacy landscape spans multiple regimes — PIPEDA federally, Law 25 in Quebec, provincial PIPAs in Alberta and BC, with the CPPA potentially replacing PIPEDA.
- Build documentation to the Law 25 standard — it's the strictest Canadian privacy law currently in force, and compliance with it satisfies the other regimes.
- Privacy Impact Assessments are mandatory under Law 25 — not just best practice. Every project involving personal information and every cross-border transfer needs a documented PIA.
- Quebec's penalties are severe — up to C$25M or 4% of worldwide turnover, with a private right of action.
- Consent requirements have tightened — explicit consent for sensitive information, no pre-checked boxes, and specific rules for minors.
- Automated decision-making must be disclosed — individuals must be told when decisions are made exclusively by automated processing.
- AI-assisted review can check documentation against multiple regimes simultaneously, catching gaps between PIPEDA and Law 25 requirements before regulators do.
- Monitor Bill C-27 — the CPPA would further transform Canadian privacy requirements with GDPR-level enforcement.
This article provides general information about Canadian privacy documentation requirements and is not legal advice. Privacy requirements vary by province and sector. Always consult the Office of the Privacy Commissioner of Canada and qualified legal counsel for guidance specific to your organisation.