Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · PIPEDA
Reference · LeakTrace Intelligence Team

PIPEDA.

Personal Information Protection and Electronic Documents Act
At a glance
Jurisdiction
Canada
Breach reporting deadline
As soon as feasible (no fixed deadline)
Applies to
AllPrivate Sector
Authoritative source
https://laws-lois.justice.gc.ca/eng/acts/p-8.6/
Last updated
August 5, 2026
## What it is PIPEDA is Canada's federal privacy law governing personal information handling by private-sector organizations engaged in commercial activity. Enforced by the Office of the Privacy Commissioner of Canada (OPC), it applies across Canada except in provinces with substantially similar legislation (currently Quebec, British Columbia, and Alberta for private-sector information; Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia for health information). ## Who it applies to Any organization collecting, using, or disclosing personal information in the course of commercial activity in a federally regulated jurisdiction. Federally regulated sectors (banking, telecommunications, interprovincial transportation, airlines) are covered nationwide regardless of provincial law. Cross-border data flows involving Canadians typically bring foreign organizations into PIPEDA's scope. ## Key data protection requirements PIPEDA is built on 10 Fair Information Principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Organizations must appoint a designated privacy officer, obtain meaningful consent, and safeguard personal information with security measures appropriate to sensitivity. ## Breach reporting Since November 1, 2018, PIPEDA has required organizations to: - **Report to the OPC** any breach of security safeguards involving personal information under the organization's control where a real risk of significant harm (RROSH) to an individual has occurred - **Notify affected individuals** as soon as feasible when RROSH exists - **Notify other organizations** (e.g., other service providers) that could reduce or mitigate the risk - **Maintain records** of every breach of security safeguards for 24 months, regardless of whether RROSH threshold is met — OPC can request the record at any time Reports must be made "as soon as feasible" after determining a breach has occurred; there is no fixed hour deadline, but delay itself can be evidence of failure to safeguard. ## Penalties Knowingly failing to report a breach or maintain breach records is an offence. On summary conviction, fines up to CAD $10,000; on indictment, up to CAD $100,000. Bill C-27 (Digital Charter Implementation Act, 2022) proposed penalties up to 5% of global gross revenue or CAD $25M — [VERIFY] status as of the current review; the bill has been through parliamentary review and its enactment status should be confirmed against the current parliamentary session. ## How LeakTrace aligns LeakTrace's continuous external-surface monitoring surfaces the credential and infrastructure exposures that most often precipitate reportable breaches — credentials in dark-web marketplaces, misconfigured public storage, lookalike-domain wire-fraud precursors. Evidence bundles are prepared with chain-of-custody documentation suitable for OPC submission and follow-on litigation.
Key provisions
Section 4.1 — Accountability
Organizations are responsible for personal information under their control, including information transferred to third-party service providers.
Section 4.3 — Consent
Meaningful consent is required for collection, use, or disclosure. Consent must be based on information a reasonable person would understand.
Section 4.7 — Safeguards
Personal information must be protected by security safeguards appropriate to the sensitivity of the information — physical, organizational, and technological.
Section 10.1 — Breach reporting
Report to the OPC and notify affected individuals when there is a real risk of significant harm (RROSH).
Section 10.3 — Record-keeping
Maintain records of every breach of security safeguards for 24 months, regardless of whether the RROSH threshold is met.
Recent amendments & guidance
2018-11-01
Mandatory breach reporting provisions came into force via the Digital Privacy Act (SC 2015, c. 32).
2022-06-16
Bill C-27 (Digital Charter Implementation Act, 2022) introduced — proposes replacing PIPEDA with the Consumer Privacy Protection Act (CPPA). [VERIFY current status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs