PIPEDA Compliance for Canadian Small Businesses in 2026: Bill C-8 + Quebec Law 25

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

PIPEDA STATUS IN 2026

Yes, PIPEDA is still in force. Bill C-27, the proposed Consumer Privacy Protection Act, died on the Order Paper when Parliament was prorogued in January 2025. No replacement federal privacy statute has been introduced since, so PIPEDA in its current form is the governing law as of August 2026.

The Critical Cyber Systems Protection Act (C-8) received Royal Assent on June 15, 2026 as S.C. 2026, c. 9, and it does not replace PIPEDA. Canadian SMBs that handle personal data must comply with PIPEDA’s 10 Fair Information Principles, plus Quebec Law 25 wherever a Quebec resident’s data is involved. The OPC remains the regulator that investigates and publishes findings.

Key Takeaways

  • PIPEDA applies to almost every Canadian SMB that handles identifiable customer records across provincial or national borders, with no headcount threshold for the Accountability or Safeguards principles.
  • Across our 30 Canadian SMB client PIPEDA engagements from 2024 to 2026, the two most-missed principles were Accountability (no named privacy officer) and Safeguards (no documented vendor due diligence).
  • Quebec Law 25 has been in full force since September 22, 2024 and binds any business collecting data about a Quebec resident. Exposure runs to the greater of CA$10M or 2% of worldwide turnover as an administrative penalty, and the greater of CA$25M or 4% as a penal fine.
  • Law 25 does not set a 72-hour breach clock. Section 3.5 says notify the Commission d’accès à l’information promptly. The 72-hour figure repeated across Canadian compliance content is imported from GDPR Article 33.
  • Bill C-8 does not replace PIPEDA. It overlays cybersecurity-program obligations on designated operators in telecom, finance, energy and transportation, and reaches SMBs through prime-contractor flow-down as a 2026 to 2027 procurement gate.
  • The minimum documented evidence the OPC and CAI expect is a privacy policy naming a privacy officer, plus a breach response runbook with named notification triggers and a maintained incident register.

Book a Free PIPEDA Readiness Review

What is PIPEDA, and does it apply to a Canadian SMB?

According to the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (2026), the statute governs every organization that collects, uses or discloses personal information in the course of commercial activity. Parliament wrote no small-business carve-out into it. Headcount, revenue and sector change nothing about whether the Act binds you.

PIPEDA has been the federal Canadian privacy law since 2000, and it reaches almost every SMB that moves customer records across a provincial or national border. There is no size threshold and no revenue floor anywhere in the Act.

Alberta, British Columbia, and Quebec have provincial laws Ottawa has declared substantially similar, so PIPEDA steps aside for activity that stays inside one of those three provinces. It returns the moment data crosses a border, which catches almost every cloud-using SMB in the country.

Fusion Computing builds PIPEDA-aligned safeguards for small businesses across Ontario and British Columbia, from encryption baselines to tested breach runbooks.

PIPEDA, Quebec Law 25 and the new cyber-security regime each push Canadian SMBs toward documented monitoring and incident evidence. The contractual model most SMBs pick to supply that evidence trail is an MSSP. See our guide on what an MSSP is and how it fits Canadian regulatory requirements.

PIPEDA breach-notification timing is incompatible with the average 241-day industry dwell time. For the practical control most Canadian SMBs use to compress the detection window from months to minutes, see our 2026 guide to managed detection and response (MDR) for Canadian SMBs.

Copilot-specific PIPEDA gap: the Pre-Copilot SharePoint Audit covers the data-layer remediation that PIPEDA places on the data collector when generative AI is added to an existing tenant.

Statutory text: laws-lois.justice.gc.ca. Regulator: Office of the Privacy Commissioner of Canada. Key amendments: 2018 Digital Privacy Act and 2018 Breach of Security Safeguards Regulations.

What does PIPEDA actually require a Canadian SMB to do?

According to the Office of the Privacy Commissioner of Canada (2026), PIPEDA’s 10 Fair Information Principles, codified in Schedule 1 of the Act, bind every private-sector organization that collects personal information for commercial activity, with no employee-count or revenue threshold. The maximum statutory penalty is CA$100,000 per offence.

PIPEDA codifies 10 Fair Information Principles plus a statutory breach-reporting obligation. Every principle applies regardless of size. Accountability and Safeguards drive most of the IT and operational work. The remaining eight drive the privacy policy, the consent flows and the individual-access procedure.

[REGULATOR QUOTE] One detail most SMB owners get wrong: the OPC does not levy fines. It investigates, publishes findings and can apply to the courts. Prosecution for the CA$100,000 offences runs through the Director of Public Prosecutions. The practical exposure for a 25-person firm is a published finding and a failed cyber-insurance renewal, well before any court sees the file.

The 10 Fair Information Principles at a glance

Principle What it requires Practical control
1. Accountability Name a privacy officer. Appointment letter; named in privacy policy.
2. Identifying Purposes State why you collect, at or before collection. Purpose statement on every form.
3. Consent Obtain meaningful consent for use and disclosure. Consent checkbox + plain-language disclosure.
4. Limiting Collection Collect only what is necessary. Annual form-field minimization review.
5. Limiting Use & Retention Use only for stated purpose; retain only as long as needed. Retention schedule and disposal log.
6. Accuracy Keep PI accurate, complete, current. Customer self-service update path.
7. Safeguards Physical, organizational, technological controls proportionate to sensitivity. MFA, encryption, RBAC, vendor DDQ, MDR.
8. Openness Make privacy policies available and clear. Privacy policy linked from site footer.
9. Individual Access Allow individuals to access and correct their PI. Data-subject access request procedure.
10. Challenging Compliance Provide a way to challenge compliance. Privacy officer contact published.

[ORIGINAL DATA] Across our 30 Canadian SMB client PIPEDA engagements from 2024 to 2026, we tracked which of the 10 principles failed on first review. This is anonymized client data drawn from readiness reviews, not a published survey.

Accountability failed most often, in roughly 6 of every 10 reviews, because nobody had been named privacy officer. Safeguards was second, because vendor due diligence existed as a habit rather than a document. The other eight principles were usually satisfied by light privacy-policy edits inside a single afternoon.

Want a principle-by-principle gap analysis? Book a free review with Mike Pearlstein, CISSP →

When must a Canadian SMB report a PIPEDA breach?

According to the Breach of Security Safeguards Regulations, SOR/2018-64 (2018), a PIPEDA breach must be reported to the OPC and to affected individuals as soon as feasible after the organization determines it creates a real risk of significant harm. Every breach needs a written record, reportable or not, kept for at least 24 months.

“Real risk of significant harm” under PIPEDA section 10.1 turns on the sensitivity of the information and the probability of misuse. Most ransomware events with confirmed data exfiltration meet that test. Failing to keep the record is itself a violation, separate from failing to report, and it is the easier one for the OPC to prove.

Quebec’s five-year incident register

Breach and incident record retention required by Canadian privacy statute Quebec Law 25 requires a confidentiality incident register kept 60 months. PIPEDA requires breach records kept 24 months. Alberta PIPA prescribes no retention period for the notice file. British Columbia PIPA imposes no register duty at all. How long you must keep the breach record Minimum retention in months, by statute (2026) Quebec Law 25 60 months PIPEDA 24 months Alberta PIPA Notice to the Commissioner required; no retention period prescribed British Columbia PIPA No mandatory breach reporting and no register duty Source: PIPEDA SOR/2018-64; Quebec Regulation respecting confidentiality incidents; Alberta PIPA s.34.1. Fusion Computing, 2026.
Build one register to the Quebec 5-year rule and it satisfies every Canadian regulator at once.

Quebec adds a second obligation PIPEDA does not have. Under the Regulation respecting confidentiality incidents, the incident register has to be kept for five years after the enterprise becomes aware of the incident, against PIPEDA’s 24 months. Build one register to the five-year rule and it satisfies both regulators.

Need a breach response runbook and incident register that survive an OPC or CAI review? Book a free 30-minute consultation →

What IT controls does PIPEDA’s Safeguards Principle require?

According to the OPC’s Securing Personal Information guidance (2026), Principle 7 calls for physical, organizational and technological safeguards proportionate to the sensitivity of the information an organization holds. The guidance names access controls, encryption, employee training and third-party oversight as the working baseline for a small business, and expects the organization to show its reasoning.

The five controls the OPC expects from an SMB

For a typical Canadian SMB that resolves to five controls:

  • MFA on every account that touches personal information.
  • Encryption at rest and in transit.
  • Role-based access reviewed quarterly.
  • Documented vendor due diligence on any cloud provider handling personal information.
  • A monitored detection and response capability that runs around the clock.

The OPC Securing personal information self-assessment tool is the canonical checklist for the first four. The fifth is the one that usually needs a partner, because detection nobody is watching at 2am is a control on paper only.

Professional practices layer their own duties on top of these five. Architecture and engineering firms, for example, also have to protect the sealed drawing itself, which we cover in cybersecurity for architecture and engineering firms.

[ORIGINAL DATA] Across our 2026 vendor due-diligence questionnaires we measured how many cloud vendors could evidence that Principle 7 baseline. Seven of ten responses were missing at least one PIPEDA-required safeguard attestation. That vendor gap, rather than the client’s own stack, is the most common reason a posture fails review.

That 7-in-10 ratio is an FC internal benchmark from Q2 2026 rather than a published statistic. It is drawn from the questionnaires we sent on behalf of clients in Toronto, Hamilton and Metro Vancouver that quarter.

Does PIPEDA require Canadian data residency or PIPEDA-compliant cloud hosting?

No. PIPEDA contains no data-localization rule, and there is no such thing as a PIPEDA-certified or PIPEDA-compliant cloud. The Act follows an accountability model. Personal information transferred to a third party for processing stays your responsibility, wherever the servers physically sit.

What the OPC expects is a contract binding the provider to a comparable level of protection, plus disclosure in your privacy policy that information may be processed outside Canada and may become accessible to foreign law enforcement. A vendor selling “PIPEDA-compliant hosting” is selling you that contract and that disclosure, not a legal status.

Quebec is stricter. Law 25 mandates a privacy impact assessment before personal information is communicated beyond the province, and the assessment must conclude the information will receive adequate protection. Our engineers found the cleanest route for most clients is a Canadian-region tenant plus one assessment per foreign processor.

Does Bill C-8 change what PIPEDA requires of my SMB?

According to Parliament of Canada LEGISinfo (2026), C-8, An Act respecting cyber security, received Royal Assent on June 15, 2026 and became S.C. 2026, c. 9. It enacts the Critical Cyber Systems Protection Act and amends the Telecommunications Act. It does not amend or replace PIPEDA.

The new Act overlays cybersecurity-program and incident-reporting obligations on designated federally-regulated critical-systems operators in telecom, finance, energy and transportation. Most Canadian SMBs fall outside the direct designation, and nothing in it changes a single word of what PIPEDA asks of a 25-person firm in Toronto or Hamilton.

The practical SMB impact arrives through procurement. Designated-sector primes are flowing the obligations down through vendor contracts as a 2026 to 2027 gate, so a 30-employee services firm with one designated-sector client may need to produce a documented cybersecurity program long before any direct designation lands.

The PIPEDA implication is alignment. A C-8 flow-down clause asks for the same evidence Principle 7 already demands, so an SMB that has documented its Safeguards work usually answers the prime’s questionnaire without new spend.

“Don’t wait for Bill C-8. PIPEDA is the operating regime today, and the controls that satisfy a Bill C-8 flow-down are the same ones that satisfy PIPEDA Principle 7. Build to Quebec Law 25, the strictest of the three. The SMBs caught short in 2026 are treating Bill C-8 as a future problem, not a vendor-contract gate already arriving from primes.”

Mike Pearlstein, CISSP, CEO, Fusion Computing Limited

Drawn from a 2026 PIPEDA readiness review across Ontario and British Columbia clients.

Statutory status: Parliament of Canada LEGISinfo, C-8, 45th Parliament, Royal Assent June 15, 2026, S.C. 2026, c. 9. Policy frame: Innovation, Science and Economic Development Canada at ised-isde.canada.ca. Full breakdown: What Is Bill C-8? A Canadian SMB Guide.

Do I have to comply with Quebec Law 25 if I’m not based in Quebec?

According to the Commission d’accès à l’information du Québec (2026), the modernized private-sector Act has applied in full since September 22, 2024, when the data-portability right came into force. The trigger is the residency of the individual rather than the address of the business, so an Ontario or British Columbia firm with one Quebec customer is in scope.

Yes. If you collect personal information about a Quebec resident you are covered, regardless of where the business is headquartered. Law 25 reaches extra-territorially on the same residency logic GDPR uses for EU data subjects.

Four obligations sit on top of PIPEDA. Notification to the CAI promptly after a confidentiality incident presenting a risk of serious injury. A privacy impact assessment for technology projects involving personal information and for transfers outside Quebec. A publicly named Person In Charge of the Protection of Personal Information. A five-year incident register.

The penalty structure is two-tier, and most summaries only quote the larger number. Administrative monetary penalties run to the greater of CA$10M or 2% of worldwide turnover. Penal fines run from CA$15,000 to the greater of CA$25M or 4%, and can be doubled for a repeat offence.

In our experience unrecognized Law 25 exposure is the second-most-common gap behind vendor due diligence. It shows up in clients with no Quebec head office and no Quebec revenue line, who still have one Quebec customer, one remote hire, or one payroll record.

PIPEDA vs Quebec Law 25: where the deltas matter

PIPEDA and Quebec Law 25 stack rather than substitute. The table below pulls the per-area deltas Canadian SMBs hit most often during compliance reviews. Build documentation to the stricter of the two; the same control set satisfies both.

Compliance area PIPEDA requirement Quebec Law 25 requirement Practical action
Privacy notice Openness principle: clear, accessible privacy policy. Same, plus transparency on automated decisions and cross-border transfers. Publish one notice that satisfies both; flag Quebec residents.
Consent Meaningful consent; opt-out tolerated for low-sensitivity uses. Express consent for sensitive PI; granular by purpose. Default to express consent on sensitive fields; document granularity.
Breach notification “As soon as feasible” after real risk of significant harm; 24-month record retention. Notify the CAI “promptly” (s.3.5) on risk of serious injury. No fixed hour count in the statute. Set an internal 72-hour target and log the timestamp of the risk decision.
Privacy officer Accountability principle: named privacy officer, no employee-count threshold. Person In Charge of Personal Information, publicly named. Appoint a single person to both roles; publish contact in the privacy policy.
Cross-border transfers Accountability follows the data; vendor due diligence required. Mandatory privacy-impact assessment before transferring PI outside Quebec. Document a PIA for every US or non-Quebec cloud provider.
Automated decisions No explicit statutory rule; covered by Accountability and Openness. Disclosure of automated decision-making and a right to explanation. Add an AI/automated-decisions clause to the privacy notice if any are used.
Individual rights Access and correction (Principle 9). Access, correction, deletion, portability, and de-indexing. Extend the data-subject access request procedure to cover Law 25 rights.
Records and evidence Breach register retained 24 months; vendor contracts; consent logs. Incident register retained 5 years; PIA file; governance policy approved by the Person In Charge. Keep one combined evidence binder to the 5-year rule; review it at the annual tabletop.

The CAI’s guidance for the private sector is the authoritative source for the Law 25 column. Where PIPEDA and Law 25 say different things, document to the stricter rule; the regulators read the same evidence binder.

How does PIPEDA compare to GDPR, PHIPA, and Bill C-8?

According to the Office of the Privacy Commissioner of Canada (2026), Alberta, British Columbia and Quebec have private-sector laws declared substantially similar to PIPEDA, and Ontario, New Brunswick and Newfoundland and Labrador hold the same designation for health-privacy laws. Those statutes displace PIPEDA only for activity that stays inside the province.

PIPEDA is the federal privacy law for inter-provincial commercial activity. GDPR is EU-extra-territorial with far higher penalty exposure. PHIPA is Ontario health-information law. The Critical Cyber Systems Protection Act is a sector-specific cybersecurity overlay. They overlap rather than replace each other, and a Canadian SMB serving several jurisdictions usually carries duties under three of the four at once.

Cross-border processing is where the overlaps bite hardest. Our guide to cross-border PHI, the CLOUD Act and Law 25 works through the three PHIPA hooks, Law 25 s.17, and why Canadian residency is a control you choose rather than a statutory rule.

Law Jurisdiction Trigger Maximum penalty
PIPEDA Canada (inter-provincial) Personal information for commercial activity CA$100K per offence
Quebec Law 25 Quebec residents (extra-territorial) PI about a Quebec resident Admin: CA$10M or 2%. Penal: CA$25M or 4%
GDPR EU residents (extra-territorial) PI about an EU data subject EUR 20M or 4% of turnover
PHIPA Ontario health PI Health information custodian in Ontario CA$200K (individual) / CA$1M (org)
Bill C-8 Federal critical-systems sectors Designated cyber system Sector-specific (substantial)

The Information and Privacy Commissioner of Ontario is the regulator for PHIPA. Most Canadian SMBs only need to formally implement PIPEDA, Law 25 and any sector-specific obligations. GDPR-equivalent practice flows in only when EU resident data is involved.

PIPA vs PIPEDA: which law applies in Alberta and British Columbia?

Alberta and British Columbia each have a Personal Information Protection Act, and both are designated substantially similar to PIPEDA. Those provincial statutes govern activity that stays inside the province. PIPEDA governs federally regulated businesses such as banks, airlines, telecoms and interprovincial transport, and it governs any commercial transfer of records across a provincial or national border.

The practical effect for an SMB in Calgary or Vancouver is that PIPEDA is rarely escaped. One US-hosted SaaS tool, one Ontario client, one payroll processor outside the province, and the federal Act is back in scope alongside the provincial one.

Breach duty is where the three laws diverge most, and it is the delta that catches Alberta and British Columbia firms during an incident.

Statute Report to regulator? Notify individuals? Maximum fine (organization)
PIPEDA (federal) Yes, to the OPC, as soon as feasible on real risk of significant harm Yes, directly by the organization CA$100,000 per offence
Alberta PIPA (s.34.1) Yes, to the Alberta Commissioner, “without unreasonable delay” Only if the Commissioner requires it (s.37.1) CA$100,000 (CA$10,000 individual)
BC PIPA No statutory duty. Voluntary reporting only No statutory duty CA$100,000 (CA$10,000 individual)
Quebec Law 25 (s.3.5) Yes, to the CAI, promptly, on risk of serious injury Yes, directly by the enterprise Admin CA$10M or 2%; penal CA$25M or 4%

Two traps live in that table. Alberta’s section 34.1 duty runs to the Commissioner only, so a firm that assumes it must write to everyone affected is guessing at an obligation the Commissioner has not yet imposed under section 37.1.

The second trap is British Columbia. Mandatory breach notification did arrive in that province in February 2023, but it sits in the Freedom of Information and Protection of Privacy Act and binds public bodies. A private company in Burnaby is not covered by it, and British Columbia’s PIPA still contains no reporting duty of its own.

In our experience the safe design for a firm operating in more than one province is a single runbook built to the strictest applicable rule, which in practice means PIPEDA plus Quebec. Alberta and British Columbia obligations are then satisfied automatically, and there is one process to test at the annual tabletop rather than four.

Reference: Alberta PIPA is S.A. 2003, c. P-6.5 and the British Columbia PIPA is S.B.C. 2003, c. 63. Both were still in force and still carried that designation as of August 2026.

How can a Canadian SMB operationalize PIPEDA + Law 25 compliance?

According to the OPC’s PIPEDA Self-Assessment Tool (2026), a compliant organization can show a named accountable individual, a documented inventory of what it collects and why, safeguards matched to sensitivity, and a procedure for access requests and complaints. That checklist maps cleanly onto a five-step build.

The sequence: name a privacy officer, inventory personal information, document the Safeguards controls, write a breach response runbook, then run a tabletop annually. We measured end-to-end timing across our 2026 readiness engagements at 30 to 60 days for a 25 to 50-employee SMB, with Safeguards the longest step because it touches the IT stack.

The five-step build, week by week

Step Deliverable Timeline
1 Privacy officer appointment + policy update Week 1
2 PI data inventory Week 2
3 Safeguards documentation: MFA, encryption, RBAC, vendor DDQ, MDR Weeks 3 to 4
4 Breach response runbook + incident register (internal 72-hour target) Week 5
5 Annual tabletop + quarterly access review Ongoing

Want Fusion Computing to walk the five-step sequence with you? Book a free 30-minute consultation →

Get a Custom PIPEDA Readiness Roadmap

Fusion Computing builds PIPEDA and Law 25 compliance programs for Canadian businesses, led by Mike Pearlstein, CISSP, from offices serving Toronto, Hamilton and Metro Vancouver.

Ontario lawyers adapting PIPEDA controls to legal practice should also review the LawPRO insurance and AI errors disclosure obligations for Rule 7.8-2 notice-of-claim framing, and the Law Society of Ontario AI policy template for LSO clause language.

Mapping PIPEDA obligations back to tested controls is the last step. Our cybersecurity assessment checklist for Canadian SMBs scores 8 control categories and produces the evidence a breach report relies on.

PIPEDA compliance checklist: the requirements to have on file

According to the OPC’s privacy self-assessment criteria (2026), an organization demonstrates compliance through documents rather than intentions. The nine artifacts below are what we hand a client at the close of an engagement, and what an investigator or an underwriter asks to see first.

The nine documents an investigator asks for

  • Privacy officer appointment letter. One named individual, dated, signed. Satisfies Accountability and doubles as the Quebec Person In Charge.
  • Published privacy policy. Names the officer, states collection purposes, discloses processing outside Canada. Satisfies Openness and Identifying Purposes.
  • Personal information inventory. What you hold, where it lives, which vendor touches it, how long you keep it.
  • Retention and disposal schedule. A defined period per record class, plus a log showing disposal actually happened.
  • Consent records. Form-level purpose statements and, for sensitive fields, express opt-in captured at the point of collection.
  • Vendor due-diligence file. A completed questionnaire and a contract clause per processor. This is the artifact that fails most often.
  • Safeguards evidence. MFA coverage report, encryption settings, quarterly access-review sign-off, backup restore test results.
  • Breach response runbook. Named decision-maker, risk-assessment criteria, notification templates for the OPC and the CAI.
  • Incident register. Every incident logged whether reportable or not, kept 24 months for PIPEDA and 5 years for Quebec.

Nothing on that list needs new software. Eight of the nine are documents, and the ninth is a set of exports from systems you already run. For a 25 to 50-employee firm we see the full set assembled in 30 to 60 days, most of it internal time.

Frequently asked questions

Does PIPEDA apply to my small business in Canada?

Yes, for almost every Canadian SMB. PIPEDA is the federal privacy law for private-sector commercial activity and applies to any organization handling personal information across provincial or national borders, regardless of employee count or revenue. Alberta, British Columbia, and Quebec have substantially-similar provincial laws that cover intra-provincial activity, but PIPEDA still applies the moment data crosses a border, which catches almost every cloud-using SMB.

What are the penalties for violating PIPEDA?

PIPEDA’s maximum statutory penalty is CA$100,000 per offence, prosecuted through the Director of Public Prosecutions rather than fined by the OPC directly. The broader pressure is reputational, because OPC findings are published and Canadian cyber-insurance underwriters increasingly ask for proof of PIPEDA-aligned controls at renewal.

Quebec Law 25 exposure is two-tier and much larger: administrative penalties to the greater of CA$10M or 2% of worldwide turnover, and penal fines to the greater of CA$25M or 4%. One Quebec customer changes the calculus for an SMB.

What does PIPEDA require after a data breach?

Notification to the OPC and affected individuals as soon as feasible after determining the breach poses a real risk of significant harm. Every breach must be recorded and retained for at least 24 months, including breaches below the reporting threshold. If a Quebec resident is affected, Law 25 section 3.5 requires notifying the CAI promptly, with no fixed hour count, and the Quebec incident register must be kept five years.

Do I need a privacy policy to comply with PIPEDA?

Yes, plus a breach response runbook. The privacy policy satisfies the Openness principle and names the officer required by Accountability. The runbook operationalizes the Breach of Security Safeguards Regulations and the Law 25 prompt-notification duty. Together those two artifacts, plus a maintained incident register, are the minimum documentation the OPC and CAI expect to see during an investigation.

What IT security controls does PIPEDA require?

The Safeguards Principle calls for physical, organizational and technological controls proportionate to sensitivity. For a typical SMB that means phishing-resistant MFA on every account that touches PI, encryption at rest and in transit, role-based access with quarterly review, vendor due-diligence questionnaires for cloud providers, and a documented detection and response capability.

Is PIPEDA being replaced by a new Canadian privacy law?

Not as of August 2026. Bill C-27, carrying the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act, died on the Order Paper when Parliament was prorogued in January 2025, and no replacement has been tabled since. C-8 received Royal Assent on June 15, 2026 as a cybersecurity-program overlay for designated critical-systems sectors, leaving PIPEDA in its current form as the governing federal privacy law.

How is PIPEDA different from GDPR?

Jurisdiction, consent model, and penalty exposure. PIPEDA is federal Canadian law for inter-provincial commercial activity; GDPR is EU-extra-territorial covering any EU data subject. PIPEDA uses meaningful-consent that tolerates opt-out in many cases; GDPR demands explicit affirmative consent for many categories. PIPEDA’s CA$100K cap is dwarfed by GDPR’s EUR 20M or 4% of turnover. Canadian SMBs only encounter GDPR if they process EU resident data.

Who in my SMB owns PIPEDA compliance?

PIPEDA’s Accountability principle requires a named privacy officer. There is no employee-count threshold and no requirement that the role be full-time. In a sub-50-employee SMB it is typically held by a co-owner, operations lead, or office manager, with the appointment documented in the privacy policy. Quebec Law 25 adds a parallel Person In Charge requirement that the same individual usually fills.

Does PIPEDA require my data to be stored in Canada?

No. PIPEDA contains no data-residency rule and no cloud certification exists, so “PIPEDA-compliant hosting” is a marketing label rather than a legal status. Under the accountability model you stay responsible for personal information you transfer to a processor, so the OPC expects a contract imposing comparable protection plus a privacy-policy disclosure that data may be handled outside Canada. Quebec Law 25 adds a mandatory privacy impact assessment before any transfer outside the province.

Does PIPEDA apply to my employees’ personal information?

Only if you are a federal work, undertaking or business, such as a bank, airline, telecom or interprovincial trucking firm. For those employers PIPEDA covers employee records. A provincially regulated employer in Alberta, British Columbia or Quebec is covered by that province’s private-sector law instead. In the remaining provinces there is no general private-sector employee privacy statute, which surprises most owners we walk through a data inventory.

What does PIPEDA compliance cost a Canadian small business?

The documentation work is measured in days, not dollars. Across our 2026 readiness engagements a 25 to 50-employee build ran 30 to 60 days end to end, most of it internal time on the privacy officer appointment, the data inventory and the runbook. The recurring cost sits in the Safeguards controls, which for most Canadian SMBs are delivered inside a managed cybersecurity plan at CA$130 to CA$180 per user per month.

Will my cyber insurer ask for PIPEDA evidence at renewal?

Increasingly yes. Canadian underwriters now ask for the same artifacts an OPC investigation would request: the named privacy officer, MFA coverage across accounts touching personal information, encryption, quarterly access reviews and a tested breach runbook. In our 2026 renewals the two questions that stalled files most often were MFA coverage percentage and the date of the last tabletop exercise, both of which are Principle 7 evidence.

Health-sector custodians answer to PHIPA before PIPEDA, and PHIPA sets no 72-hour clock. Our guide to managed IT services for healthcare providers covers what the Act actually requires.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Led by a CISSP-led team, Fusion supports organizations with 10 to 150 employees from Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611