Reference · LeakTrace Intelligence Team
PIPEDA.
Personal Information Protection and Electronic Documents Act
At a glance
- Jurisdiction
- Canada
- Breach reporting deadline
- As soon as feasible (no fixed deadline)
- Applies to
- AllPrivate Sector
- Authoritative source
- https://laws-lois.justice.gc.ca/eng/acts/p-8.6/
- Last updated
- August 5, 2026
## What it is
PIPEDA is Canada's federal privacy law governing personal information handling by private-sector organizations engaged in commercial activity. Enforced by the Office of the Privacy Commissioner of Canada (OPC), it applies across Canada except in provinces with substantially similar legislation (currently Quebec, British Columbia, and Alberta for private-sector information; Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia for health information).
## Who it applies to
Any organization collecting, using, or disclosing personal information in the course of commercial activity in a federally regulated jurisdiction. Federally regulated sectors (banking, telecommunications, interprovincial transportation, airlines) are covered nationwide regardless of provincial law. Cross-border data flows involving Canadians typically bring foreign organizations into PIPEDA's scope.
## Key data protection requirements
PIPEDA is built on 10 Fair Information Principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Organizations must appoint a designated privacy officer, obtain meaningful consent, and safeguard personal information with security measures appropriate to sensitivity.
## Breach reporting
Since November 1, 2018, PIPEDA has required organizations to:
- **Report to the OPC** any breach of security safeguards involving personal information under the organization's control where a real risk of significant harm (RROSH) to an individual has occurred
- **Notify affected individuals** as soon as feasible when RROSH exists
- **Notify other organizations** (e.g., other service providers) that could reduce or mitigate the risk
- **Maintain records** of every breach of security safeguards for 24 months, regardless of whether RROSH threshold is met — OPC can request the record at any time
Reports must be made "as soon as feasible" after determining a breach has occurred; there is no fixed hour deadline, but delay itself can be evidence of failure to safeguard.
## Penalties
Knowingly failing to report a breach or maintain breach records is an offence. On summary conviction, fines up to CAD $10,000; on indictment, up to CAD $100,000. Bill C-27 (Digital Charter Implementation Act, 2022) proposed penalties up to 5% of global gross revenue or CAD $25M — [VERIFY] status as of the current review; the bill has been through parliamentary review and its enactment status should be confirmed against the current parliamentary session.
## How LeakTrace aligns
LeakTrace's continuous external-surface monitoring surfaces the credential and infrastructure exposures that most often precipitate reportable breaches — credentials in dark-web marketplaces, misconfigured public storage, lookalike-domain wire-fraud precursors. Evidence bundles are prepared with chain-of-custody documentation suitable for OPC submission and follow-on litigation.
Key provisions
- Section 4.1 — Accountability
- Organizations are responsible for personal information under their control, including information transferred to third-party service providers.
- Section 4.3 — Consent
- Meaningful consent is required for collection, use, or disclosure. Consent must be based on information a reasonable person would understand.
- Section 4.7 — Safeguards
- Personal information must be protected by security safeguards appropriate to the sensitivity of the information — physical, organizational, and technological.
- Section 10.1 — Breach reporting
- Report to the OPC and notify affected individuals when there is a real risk of significant harm (RROSH).
- Section 10.3 — Record-keeping
- Maintain records of every breach of security safeguards for 24 months, regardless of whether the RROSH threshold is met.
Recent amendments & guidance
2018-11-01
Mandatory breach reporting provisions came into force via the Digital Privacy Act (SC 2015, c. 32).
2022-06-16
Bill C-27 (Digital Charter Implementation Act, 2022) introduced — proposes replacing PIPEDA with the Consumer Privacy Protection Act (CPPA). [VERIFY current status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs