{"id":801,"date":"2022-01-17T10:37:00","date_gmt":"2022-01-17T10:37:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=801"},"modified":"2026-03-12T08:19:52","modified_gmt":"2026-03-12T08:19:52","slug":"pipeda","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/us\/pipeda\/","title":{"rendered":"Canada\u2019s PIPEDA"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-quick-summery\">Quick summery<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-canada-s-pipeda-in-brief\">Canada\u2019s PIPEDA, in brief<\/h3>\n\n\n\n<p>Canada has several federal data privacy laws and even more provincial ones, which all make up an interwoven network of data protection across the country.<\/p>\n\n\n\n<p>The Personal Information Protection and Electronic Documents Act (PIPEDA) is the federal data privacy law that governs the commercial use of Canadian residents\u2019 personal information.<\/p>\n\n\n\n<p>In PIPEDA, personal information is defined as any kind of data that can identify an individual, including the data that most cookies and trackers collect from your website\u2019s users, such as IP addresses, unique IDs, search and browser history.<\/p>\n\n\n\n<p><strong>Did you know that websites on average have 20 cookies in use?<br><\/strong><a href=\"\/\">Scan your website for free to detect and control them all<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4045\/lewis-parsons-gk-net0_iju-unsplash.jpg?width=236&amp;&amp;mode=max\" alt=\"Person holding out an orange leaf - Cookiebot\" width=\"616\" height=\"770\"\/><figcaption class=\"wp-element-caption\">Canada\u2019s PIPEDA protects Canadian residents from unwanted harvest of their personal information.<\/figcaption><\/figure>\n\n\n\n<p><strong>PIPEDA<\/strong>&nbsp;took effect in 2000 and has been amended several times to meet the changes that have swept our digital landscapes in the past two decades.<\/p>\n\n\n\n<p>Most notably, <strong>PIPEDA<\/strong>&nbsp;is scheduled to receive <a href=\"https:\/\/iapp.org\/news\/a\/federal-privacy-reform-in-canada-the-consumer-privacy-protection-act\/\" target=\"_blank\" rel=\"noreferrer noopener\">a major overhaul sometime in 2021<\/a>&nbsp;and be turned into the <strong>Consumer Privacy Protection Act (CPPA)<\/strong>, expanding rights for Canadian residents and updating the current consent regime, as part of the implementation of <a href=\"https:\/\/www.ic.gc.ca\/eic\/site\/062.nsf\/eng\/h_00109.html\" target=\"_blank\" rel=\"noreferrer noopener\">Canada\u2019s Digital Charter<\/a>.<\/p>\n\n\n\n<p>Canada\u2019s PIPEDA has received <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/international-dimension-data-protection\/adequacy-decisions_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">an adequacy decision from the EU Commission<\/a>, ensuring the free flow of personal data back and forth between Canada and the EU (note: only PIPEDA has been deemed adequate, and it is therefore only data transfers to and from the commercial, private sector of Canada that is secured with the EU.<\/p>\n\n\n\n<p>In short, Canada\u2019s <strong>PIPEDA<\/strong>&nbsp;regulates all gathering, use and disclosure of personal information in the private sector through its <strong>10 PIPEDA Principles<\/strong>; chief among them the requirements that you inform users in detail about your website\u2019s data collection, and <strong>obtain their prior, meaningful consent<\/strong>.<\/p>\n\n\n\n<p>PIPEDA is enforced by the <a href=\"https:\/\/www.priv.gc.ca\/en\/\" target=\"_blank\" rel=\"noreferrer noopener\">Canadian Privacy Commissioner (OPC)<\/a>&nbsp;and applies to all websites and companies in the world that process personal information from Canadian residents for commercial use.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see if you have users from Canada<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4047\/michelle-spollen-p22afmgmuuc-unsplash.jpg?width=217&amp;&amp;mode=max\" alt=\"Person holding 40 Canadian dollars - Cookiebot\" width=\"578\" height=\"770\"\/><figcaption class=\"wp-element-caption\">Fines for non-compliance with PIPEDA can reach CAD 100,000.<\/figcaption><\/figure>\n\n\n\n<p><strong>Canada\u2019s PIPEDA quick breakdown<\/strong>&nbsp;\u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;took effect in April 2000 and was last amended in 2018. An overhaul of the law is scheduled to take place in 2021, repealing and replacing core parts of PIPEDA with the new Consumer Privacy Protection Act (CPPA).<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;governs all gathering, use and disclosure for commercial purposes of the personal information of Canadian residents. Use of personal information by the federal government is regulated by the separate federal Privacy Act.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;defines personal information as information about an identifiable individual, which includes IP addresses, cookies, search and browser history collected by most websites through third-party cookies and trackers. Some data can be viewed as more sensitive than other, e.g. medical data and sexual orientation, and will require express consent from users.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;applies to any website in the world that processes personal information from Canadian residents for commercial use.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;empowers Canadian users with the rights to access their personal information, correct it and to challenge your website\u2019s PIPEDA compliance through the Privacy Commissioner.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;operates by its 10 PIPEDA Principles, which regulate compliance for websites, companies and organizations processing Canadian residents\u2019 personal information. They include the requirements to inform users about all data collection operations and to obtain explicit or implicit consent from users, depending on the nature of the data you collect.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;does not prohibit transfers of personal information outside of Canada, but does hold you liable for privacy breaches and non-compliance.<\/li>\n\n\n\n<li><strong>Canada\u2019s PIPEDA<\/strong>&nbsp;is enforced by the Privacy Commissioner.<\/li>\n\n\n\n<li>Non-compliance with <strong>Canada\u2019s PIPEDA<\/strong>&nbsp;can result in fines up to CAD 100,000.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4048\/stefan-spassov-hkn2zde2ga4-unsplash.jpg?width=354&amp;&amp;mode=max\" alt=\"Person sitting on rocks with the sea in the background at sunset - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">Canada\u2019s PIPEDA revolves around \u201cmeaningful consent\u201d, which you must obtain prior to gathering user data.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot consent management platform (CMP)<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies and trackers are in operation<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipeda-compliance-with-cookiebot-cmp\">PIPEDA compliance with Cookiebot CMP<\/h2>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>\u00a0by\u00a0<a href=\"https:\/\/usercentrics.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Usercentrics<\/a>\u00a0is the world\u2019s leading solution for controlling cookies and trackers on your website to ensure compliance with all major data privacy laws on the planet, including Canada\u2019s PIPEDA,\u00a0<a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>,\u00a0<a href=\"\/en\/uk-gdpr\/\">UK\u2019s GDPR<\/a>,\u00a0<a href=\"\/en\/ccpa\/\">California\u2019s CCPA<\/a>,\u00a0<a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>,\u00a0<a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>\u00a0and many others.<\/p>\n\n\n\n<p>As Canada\u2019s PIPEDA require you to<strong>&nbsp;inform users<\/strong>&nbsp;and <strong>obtain their consent<\/strong>, PIPEDA compliance means knowing and controlling all cookies and tracking technologies in use on your website, plus having a solution for collecting the valid consents of users to all of those cookies that you use.<\/p>\n\n\n\n<p>This is a time-consuming and difficult task for any website, regardless of size and shape.<\/p>\n\n\n\n<p>Luckily, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is a <strong>plug-and-play solution<\/strong>&nbsp;that has completely automated the entire PIPEDA compliance process for you and your website.<\/p>\n\n\n\n<p>Built around\u00a0<strong>a powerful scanner<\/strong>\u00a0that detects every single cookie and similar tracking technology,\u00a0Cookiebot CMP\u00a0gives you total insight into your domain\u2019s personal information processing activities.<\/p>\n\n\n\n<p>Cookiebot CMP\u00a0gives you detailed information on each cookie on your website, including its\u00a0<strong>purpose<\/strong>,\u00a0<strong>duration<\/strong>,\u00a0<strong>technical specifications<\/strong>\u00a0and\u00a0<strong>provider<\/strong>\u00a0\u2013 facts that you need to inform your users about as part of your PIPEDA compliance.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770\" height=\"449\"\/><figcaption class=\"wp-element-caption\">Cookiebot CMP consent banner for PIPEDA compliance<\/figcaption><\/figure>\n\n\n\n<p>Through highly customizable consent banners that can be shaped to fit the compliance requirements specific to any region\u2019s data privacy law, including Canada\u2019s PIPEDA, Cookiebot CMP offers a simple way of collecting users\u2019 valid, informed consent.<\/p>\n\n\n\n<p>Cookiebot CMP safely stores all collected consents, automatically renews consent on a regular basis and makes it easy for your website\u2019s users to withdraw their consent as easily as they gave it.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PIPEDA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/pipeda_brief\/\" target=\"_blank\" rel=\"noreferrer noopener\">Visit the Canadian Privacy Commissioner (OPC) for more on PIPEDA compliance<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/google-consent-mode\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-canada-s-pipeda-in-detail\">Canada\u2019s PIPEDA, in detail<\/h2>\n\n\n\n<p>Let\u2019s break down <strong>Canada\u2019s PIPEDA<\/strong>&nbsp;even further and look at its<strong>&nbsp;10 PIPEDA Principles<\/strong>, how it interacts with <strong>provincial data privacy laws<\/strong>&nbsp;around Canada (e.g. Albert and Ontario), and hold it up against the <strong>EU\u2019s GDPR for comparison<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/laws-lois.justice.gc.ca\/ENG\/ACTS\/P-8.6\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">See the full PIPEDA law text<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-10-pipeda-principles\">The 10 PIPEDA Principles<\/h3>\n\n\n\n<p>Canada\u2019s PIPEDA revolves around the ten so-called <strong>fair information principles<\/strong>&nbsp;that spell out the rules and regulations around the use of personal information for commercial purposes.<\/p>\n\n\n\n<p>PIPEDA\u2019s definition of <strong>commercial purpose<\/strong>&nbsp;includes acts such as selling or trading of your users\u2019 data, e.g. in exchange for analytics services or marketing schemes.<\/p>\n\n\n\n<p>If your website collects personal information from Canadian residents, such as IP addresses or search history, and then trades this information with a third-party service in exchange for tracking of users or marketing services, <strong>you are likely liable for PIPEDA compliance<\/strong>&nbsp;\u2013 no matter where in the world you and your website is operated from.<\/p>\n\n\n\n<p><strong>Did you know that websites on average have 20 cookies in use?<br><\/strong><a href=\"\/\">Scan your website for free to detect and control them all<\/a><\/p>\n\n\n\n<p>The 10 PIPEDA Principles are \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Accountability<\/li>\n\n\n\n<li>Identifying purposes<\/li>\n\n\n\n<li>Consent<\/li>\n\n\n\n<li>Limiting<\/li>\n\n\n\n<li>Collection<\/li>\n\n\n\n<li>Limiting use, disclosure, and retention accuracy<\/li>\n\n\n\n<li>Safeguards<\/li>\n\n\n\n<li>Openness<\/li>\n\n\n\n<li>Individual Access<\/li>\n\n\n\n<li>Challenging compliance<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4049\/john-lee-omneobyhjxy-unsplash.jpg?width=360&amp;&amp;mode=max\" alt=\"Canadian lake with mountains &amp; trees in the background - Cookiebot\" width=\"770\" height=\"551\"\/><figcaption class=\"wp-element-caption\">The ten PIPEDA Principles apply to all personal information processing for commercial use.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-1-accountability\">PIPEDA Principle 1 \u2013 Accountability<\/h3>\n\n\n\n<p>The first PIPEDA Principle makes it clear that <strong>you are responsible for all personal information that your website collects<\/strong>, and that you must have <strong>a designated representative<\/strong>&nbsp;in charge of ensuring your PIPEDA compliance.<\/p>\n\n\n\n<p>Additionally, you need <strong>to develop and implement privacy policies and practices<\/strong>, which must be readily available for your users to read.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_accountability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-2-identifying-purposes\">PIPEDA Principle 2 \u2013 Identifying Purposes<\/h3>\n\n\n\n<p>Why does your website collect the personal information that it does?<\/p>\n\n\n\n<p>This is the question that the second PIPEDA Principle requires you to answer \u2013 <strong>in detail<\/strong>&nbsp;and <strong>prior to actually collecting<\/strong>&nbsp;any personal information from your users.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_purposes\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-3-consent\">PIPEDA Principle 3 - Consent<\/h3>\n\n\n\n<p>This is the most important PIPEDA Principle of all.<\/p>\n\n\n\n<p>In a nutshell: <strong>you must obtain the meaningful consent from users before collecting, using and sharing their personal information<\/strong>.<\/p>\n\n\n\n<p><em>\u201cMeaningful consent\u201d<\/em>&nbsp;under PIPEDA involves informing your users of exactly what they are consenting to, e.g. telling them what cookies your website uses, why and what the data is going to be used for.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4050\/hermes-rivera-ahhn48-zkwo-unsplash.jpg?width=367&amp;&amp;mode=max\" alt=\"Flagpole with the flag of Canada  - Cookiebot\" width=\"770\" height=\"410\"\/><figcaption class=\"wp-element-caption\">Consent can be both express and implied, depending on the sensitivity of the personal information.<\/figcaption><\/figure>\n\n\n\n<p>PIPEDA states that consent is only valid, if it is \u201creasonable to expect\u201d that your users understand the nature, purpose and consequence of your website\u2019s personal information processing.<\/p>\n\n\n\n<p>Additionally, consent under PIPEDA can either be <strong>implied<\/strong> <strong>consent<\/strong>&nbsp;or <strong>express<\/strong> <strong>consent<\/strong>.<\/p>\n\n\n\n<p><strong>Implied consent<\/strong>&nbsp;means that your website can collect personal information from users on the assumption that they will consent, without the need for them to explicitly and actively give their consent.<\/p>\n\n\n\n<p>However, for <strong>implied consent<\/strong>&nbsp;to be valid, you must still inform your users prior to collection about \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>what kinds of personal information your website will collect,<\/li>\n\n\n\n<li>for what purposes your website collets this data,<\/li>\n\n\n\n<li>who you share this data with (e.g. third parties such as Google or Facebook),<\/li>\n\n\n\n<li>and what the risks and consequences are for users.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PIPEDA compliance today<\/a><\/p>\n\n\n\n<p><strong>Express consent<\/strong>&nbsp;means the active and explicit action on part of the user that constitutes consent, e.g. clicking a button or ticking a box to signal that they allow the subsequent collection of their personal information.<\/p>\n\n\n\n<p>This form of consent is obligatory when processing personal information that can be considered sensitive of nature \u2013 e.g. medical and health data, information about an individual\u2019s sexual orientation or religious beliefs.<\/p>\n\n\n\n<p>However, making sure that you always collect express from all your website\u2019s users is a safe way to avoid any grey areas of potential non-compliance with PIPEDA.<\/p>\n\n\n\n<p>Additional requirements for valid consent include \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inform users in an easily accessible way, e.g. your website\u2019s privacy policy.<\/li>\n\n\n\n<li>Users must be able to revoke their consent at any time, as easily as they gave it.<\/li>\n\n\n\n<li>Reobtain consent from users, when you make significant changes to your website\u2019s cookie-setup, its privacy practices, or introduce new uses and purposes for its data collection, among other things.<\/li>\n\n\n\n<li>Obtain express consent from a parent or guardian for children under the age of 13.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP free for 14 days<\/a>\u00a0\u2013 or forever if you have a small website.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_consent\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4051\/alex-shutin-uhn-u0ssxfq-unsplash.jpg?width=377&amp;&amp;mode=max\" alt=\"Toronto waterfront at night  - Cookiebot\" width=\"770\" height=\"514\"\/><figcaption class=\"wp-element-caption\">Canada\u2019s PIPEDA applies to any website in the world, regardless of its location, if it uses personal information from inside the country.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-4-limiting-collection\">PIPEDA Principle 4 \u2013 Limiting Collection<\/h3>\n\n\n\n<p>The crux of the fourth PIPEDA Principle is this: your website is not allowed to collect personal information in ways that <strong>exceed or are beside the stated purposes<\/strong>, to which your users have already consented.<\/p>\n\n\n\n<p>If you want to use personal information for different purposes, you must <strong>rewrite your privacy policy<\/strong>&nbsp;to include these new purposes \u2013 and <strong>renew the consent<\/strong>&nbsp;of your users.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_collection\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-5-limiting-use-disclosure-and-retention\">PIPEDA Principle 5 \u2013 Limiting Use, Disclosure, and Retention<\/h3>\n\n\n\n<p>Similar to the fourth, the fifth PIPEDA principle requires you to only use and disclose personal information in the ways that you\u2019ve stated in your privacy policy, and to which your users have already consented.<\/p>\n\n\n\n<p>You are also <strong>only allowed to keep<\/strong>&nbsp;personal information (known as \u201cretention\u201d) for as long as needed to serve the purposes that you\u2019ve informed your users about and to which they\u2019ve consented.<\/p>\n\n\n\n<p>As with the previous principle, should you change the ways you want to use or share personal information on your website, <strong>you must inform users anew and obtain their consent again<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_use\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-6-accuracy\">PIPEDA Principle 6 \u2013 Accuracy<\/h3>\n\n\n\n<p>It\u2019s a requirement for PIPEDA compliance that the personal information your website collects is <strong>accurate<\/strong>&nbsp;and <strong>complete<\/strong>, as well as <strong>up to date<\/strong>.<\/p>\n\n\n\n<p>Canadian residents have the <strong>right to access<\/strong>&nbsp;data collected about them and the <strong>right to have it corrected<\/strong>, should they find it <strong>inaccurate<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_accuracy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4052\/james-thomas-ug-m_ngzmfm-unsplash.jpg?width=363&amp;&amp;mode=max\" alt=\"Toronto skyline - Cookiebot\" width=\"770\" height=\"578\"\/><figcaption class=\"wp-element-caption\">Canadian users are empowered with the enforceable rights of access and correction.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-7-safeguards\">PIPEDA Principle 7 \u2013 Safeguards<\/h3>\n\n\n\n<p>It is also your responsibility to keep collected personal information <strong>safe<\/strong>&nbsp;and <strong>secure<\/strong>.<\/p>\n\n\n\n<p>Though Canada\u2019s PIPEDA doesn\u2019t specify exactly what kinds of security measures you must take on your website in order to protect your users\u2019 personal information, this PIPEDA principle helps you get <strong>an overview of the safeguards required<\/strong>.<\/p>\n\n\n\n<p>Among the proposed safeguards in PIPEDA are \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Up to date<\/strong>&nbsp;encryption technologies, fire walls and security systems,<\/li>\n\n\n\n<li>Organizational <strong>practices&nbsp;<\/strong>and<strong>&nbsp;controls<\/strong>&nbsp;for handling personal information,<\/li>\n\n\n\n<li><strong>Regular review<\/strong>&nbsp;of security and encryption measures,<\/li>\n<\/ul>\n\n\n\n<p>Personal information must be protected by appropriate security <strong>relative to the sensitivity<\/strong>&nbsp;of the information. Is the data collected of a more sensitive nature, e.g. data on your users\u2019 sexual orientation, it will require stronger safeguards than less sensitive data.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_safeguards\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-8-openness\">PIPEDA Principle 8 \u2013 Openness<\/h3>\n\n\n\n<p>Your website needs to be transparent, honest and clear about the kinds of personal information it collects, what it uses it for and the ways in which it gathers and shares it. This eight PIPEDA Principle clarifies that your privacy policies and information to users must be easy to understand and written in plain language (i.e. not long legal texts). Information to be open about to your website\u2019s users include \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>individual responsible for your website\u2019s privacy policies and practices,<\/li>\n\n\n\n<li>contact information for users to send access requests via,<\/li>\n\n\n\n<li>information on how your users can be granted access to the personal information your website has collected about them,<\/li>\n\n\n\n<li>the ways in which users can complain to you,<\/li>\n\n\n\n<li>information on what kinds of personal information you share with third parties from your website, and the purposes.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_openness\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-9-individual-access\">PIPEDA Principle 9 \u2013 Individual Access<\/h3>\n\n\n\n<p>Canadian residents have the <strong>right to access<\/strong>&nbsp;what personal information your website has collected from them, as well as the <strong>right to have it corrected<\/strong>&nbsp;if the data not accurate or complete.<\/p>\n\n\n\n<p>This ninth PIPEDA Principle spells out how you are required to respond to such requests from users, including \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Telling users what personal information your website has collected from them,<\/li>\n\n\n\n<li>How your website has collected the data (by which means),<\/li>\n\n\n\n<li>How your website has used the collected data,<\/li>\n\n\n\n<li>With whom the data has been shared,<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-principle-10-challenging-compliance\">PIPEDA Principle 10 \u2013 Challenging Compliance<\/h3>\n\n\n\n<p>If users find that you are non-compliant with PIPEDA, e.g. because you violate or don\u2019t live up to one of the above nine PIPEDA Principles, they are <strong>legally allowed to challenge your compliance status<\/strong>.<\/p>\n\n\n\n<p>The last PIPEDA principle spells out how such challenges must be issued and how you must respond to them, i.e. by providing users with a simple way to give their complaint and informing them of their rights to refer to <a href=\"https:\/\/www.priv.gc.ca\/\" target=\"_blank\" rel=\"noreferrer noopener\">the Privacy Commissioner (OPC)<\/a>.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/principles\/p_compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more from the Privacy Commissioner (OPC)<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4053\/matthew-henry-_xytu0lcvwo-unsplash.jpg?width=363&amp;&amp;mode=max\" alt=\"Road with trees on either side with a skyscrapers in the background - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">PIPEDA governs in parallel with similar data privacy laws in Alberta, British Columbia and Quebec.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipeda-and-provincial-data-privacy-laws\">PIPEDA and provincial data privacy laws<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-and-alberta-pipeda-and-british-columbia-pipeda-and-quebec\">PIPEDA and Alberta, PIPEDA and British Columbia, PIPEDA and Quebec<\/h3>\n\n\n\n<p>Though Canada\u2019s PIPEDA is a federal data privacy law, several Canadian provinces have similar data privacy laws that are in effect in parallel with PIPEDA.<\/p>\n\n\n\n<p>The following provincial data privacy laws are <strong>considered equivalent to PIPEDA<\/strong>, so if you\u2019re in compliance with them, it means you are exempt from also seeking compliance with PIPEDA \u2013<\/p>\n\n\n\n<p>Firstly, <a href=\"https:\/\/www.oipc.ab.ca\/legislation\/pipa.aspx\" target=\"_blank\" rel=\"noreferrer noopener\">Alberta\u2019s Personal Information Protection Act (PIPA)<\/a>&nbsp;regulates the commercial use of personal information in Alberta, enforced and supervised by the <a href=\"https:\/\/www.oipc.ab.ca\/\">Information and Privacy Commissioner of Alberta<\/a>.<\/p>\n\n\n\n<p>Secondly, <a href=\"https:\/\/www.bclaws.gov.bc.ca\/civix\/document\/id\/complete\/statreg\/00_03063_01\/\" target=\"_blank\" rel=\"noreferrer noopener\">British Columbia\u2019s Personal Information Protection Act (PIPA)<\/a>&nbsp;regulates the commercial use of personal information in British Columbia, enforced and supervised by the <a href=\"https:\/\/www.oipc.bc.ca\/\" target=\"_blank\" rel=\"noreferrer noopener\">Information and Privacy Commissioner of British Columbia<\/a>.<\/p>\n\n\n\n<p>Lastly, <a href=\"https:\/\/legisquebec.gouv.qc.ca\/en\/ShowDoc\/cs\/P-39.1\" target=\"_blank\" rel=\"noreferrer noopener\">Quebec\u2019s Act Respecting the Protection of Personal Information in the Private Sector<\/a>&nbsp;regulates the commercial use of personal information in Quebec, enforced and supervised by the <a href=\"https:\/\/www.cai.gouv.qc.ca\/\" target=\"_blank\" rel=\"noreferrer noopener\">Commission d\u2019acc\u00e8s \u00e0 l\u2019information du Qu\u00e9bec<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4054\/guillaume-jaillet-eiwcd0414xq-unsplash.jpg?width=366&amp;&amp;mode=max\" alt=\"Person holding an orange leaf - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">PIPEDA compliance is not required if you\u2019re already in compliance with some provincial data laws.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for free today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies are in use<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipeda-vs-gdpr\">PIPEDA vs GDPR<\/h2>\n\n\n\n<p>Canada\u2019s PIPEDA has been in force since 2000 and reflects a pre-GDPR time of data protection (although it has been amended several times in response to changes in global data privacy).<\/p>\n\n\n\n<p>The<strong>&nbsp;biggest similarities<\/strong>&nbsp;between PIPEDA and GDPR are \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;both revolve around user consent as the mechanism that allows your website to collect and use personal information from your visitors.<\/li>\n\n\n\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;both define personal information\/personal data broadly to include common trackers, cookies and other data that your website collects every day.<\/li>\n\n\n\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;both require you to inform your users about your website\u2019s intended collection and use of their data.<\/li>\n\n\n\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;both require you to limit the use, disclosure and retention of the data, as well as to provide security and safeguards around the collected data.<\/li>\n\n\n\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;require you to only use data for the stated purpose or otherwise renew user consent. Both laws hold you accountable for ensuring the accuracy of the data.<\/li>\n\n\n\n<li><strong>PIPEDA and GDPR<\/strong>&nbsp;both empower users with the right to access their collected data, and the right to have it corrected if inaccurate.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-default\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4055\/canada-eu001.jpeg?width=365&amp;&amp;mode=max\" alt=\"Combined flag of the European Union and the Canadian flag - Cookiebot\" width=\"384\" height=\"247\"\/><figcaption class=\"wp-element-caption\">One of the biggest differences between PIPEDA and GDPR is their scope.<\/figcaption><\/figure>\n\n\n\n<p>The <strong>biggest differences<\/strong>&nbsp;between PIPEDA and GDPR are \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PIPEDA<\/strong>&nbsp;applies only to commercial use of personal information vs <strong>GDPR<\/strong>&nbsp;applies to both public and private sector use of personal data.<\/li>\n\n\n\n<li>PIPEDA considers \u201cimplied consent\u201d valid vs <strong>GDPR<\/strong>&nbsp;requires you to obtain \u201cexplicit consent\u201d.<\/li>\n\n\n\n<li><strong>PIPEDA<\/strong>&nbsp;does not have an adequacy mechanism but requires each website who wishes to transfer personal information abroad to use contractual privacy clauses vs <strong>GDPR<\/strong>&nbsp;requires a country to have an adequate level of data protection in order for your website to freely transfer personal data from the EU to it.<\/li>\n<\/ul>\n\n\n\n<p>With the <a href=\"https:\/\/iapp.org\/news\/a\/federal-privacy-reform-in-canada-the-consumer-privacy-protection-act\/\" target=\"_blank\" rel=\"noreferrer noopener\">impending 2021 overhaul of PIPEDA<\/a>, which will repeal and replace large parts of the law with the new Consumer Privacy Protection Act (CPPA), Canada\u2019s data protection regime might move even closer to EU\u2019s GDPR, bringing even stronger data privacy to Canadian users than PIPEDA offers currently.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-summary-of-canada-s-pipeda\">Summary of Canada\u2019s PIPEDA<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipeda-compliance-with-cookiebot-cmp-0\">PIPEDA compliance with Cookiebot CMP<\/h3>\n\n\n\n<p>Canada\u2019s PIPEDA is a strong and veteran data privacy law that like its EU counterpart, the GDPR, provides for a substantial consent regime, which empowers Canadian residents with actionable and enforceable rights over the personal information they share every day online.<\/p>\n\n\n\n<p>PIPEDA requires your website to <strong>obtain the valid consent<\/strong>&nbsp;from users before collecting or using any of their personal information, and to <strong>inform users about the details of your website\u2019s data collection processes<\/strong>.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>\u00a0by\u00a0<a href=\"https:\/\/usercentrics.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Usercentrics<\/a>\u00a0is a plug-and-play PIPEDA compliance solution that can automate all data privacy requirements for your website.<\/p>\n\n\n\n<p>Cookiebot CMP\u00a0offers full and automated compliance with not only Canada\u2019s PIPEDA, but the\u00a0<a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>,\u00a0<a href=\"\/en\/uk-gdpr\/\">UK\u2019s GDPR<\/a>,\u00a0<a href=\"\/en\/ccpa\/\">California\u2019s CCPA\/CPRA<\/a>,\u00a0<a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>,\u00a0<a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>,\u00a0<a href=\"\/en\/singapore-pdpa\/\">Singapore\u2019s PDPA<\/a>\u00a0and many others.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a>\u00a0\u2013 or forever if you have a small website.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about GDPR compliance<\/a><\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Quick summery Canada\u2019s PIPEDA, in brief Canada has several federal data privacy laws and even more provincial ones, which all make up an interwoven network of data protection across the country. The Personal Information Protection and Electronic Documents Act (PIPEDA) is the federal data privacy law that governs the commercial use of Canadian residents\u2019 personal [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":827,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2022\/01\/1920px-flag_of_canada_-pantone_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/comments?post=801"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media\/827"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media?parent=801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/categories?post=801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/tags?post=801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}