PIPEDA stands for the Personal Information Protection and Electronic Documents Act, a federal privacy law that applies to private sector organisations in Canada that collect, use, or disclose personal information for commercial activity.

PIPEDA regulates how businesses collect, use, and disclose personal information from customers for commercial activity. The law defines commercial activity as any activity that promotes, creates, or exchanges commercial products or services, including advertising, fundraising, buying or selling products or services, encouraging paid membership, or marketing commercial activities. It does not include activities carried out by or for government entities.

What Is Personal Information?

examples of identification examples of identification

Personal information is any factual information relating to an identifiable individual, including but not limited to:

  • Name and age
  • Home address, business address, email address
  • Health, finances, education
  • Identifying numbers (social security number, tax file number, driver’s licence, phone number)
  • Race and ethnic origin
  • DNA and blood type

Who Does PIPEDA Apply To?

PIPEDA applies to all private sector organisations in Canada that collect, use, or disclose personal information, except those in Alberta, British Columbia, or Quebec, which have their own similarly strict privacy laws.

A private sector organisation is one run by individuals or groups to turn a profit, generally outside government control: sole proprietors, partnerships, and companies of any size. Some federally regulated organisations are also subject to PIPEDA, including airports, airlines, banks, inter-provincial or international transport companies, telecommunications companies, offshore drilling operations, and radio and television broadcasters.

Your Responsibilities Under PIPEDA

fair information principles of PIPEDA

Schedule 1 of PIPEDA sets out ten fair information principles businesses must follow:

  1. Accountability
  2. Identifying Purposes
  3. Consent
  4. Limiting Collection
  5. Limiting Use, Disclosure, and Retention
  6. Accuracy
  7. Safeguards
  8. Openness
  9. Individual Access
  10. Challenging Compliance

1. Accountability

staff complying with PIPEDA

Comply with all ten principles, appoint someone responsible for PIPEDA compliance, protect personal information held by your organisation, and develop and implement best practices for handling it.

2. Identifying Purposes

Have a documented reason for collecting personal information, inform customers of that reason at or before collection, and get new consent if you want to use their data for a new purpose. For online businesses, a PIPEDA-compliant privacy policy on your website achieves this.

PIPEDA compliant privacy policy

Obtain meaningful consent, explaining your purpose for collecting information and what you’ll use it for, for any collection, use, or disclosure. Consent should only cover what’s necessary for a specified, legitimate purpose, and customers can withdraw consent at any time, subject to legal and contractual obligations. Online, this is typically achieved through a compliant privacy policy that clearly discloses what you collect, who it’s shared with, why you collect it, and any associated risks.

4. Limiting Collection

Only collect the personal information you genuinely need for a legitimate purpose, be honest about why you’re collecting it, and collect it by fair and lawful means.

5. Limiting Use, Disclosure, and Retention

limit use, disclosure and retention of personal data

Only use collected information for its intended purpose (unless required by law otherwise), retain it only as long as needed, know what information you hold and where, get new consent for new purposes, and have procedures in place for destroying data you no longer need.

6. Accuracy

Keep personal information as accurate and up to date as possible, to minimise the risk of using incorrect information when making decisions or disclosing it to third parties.

7. Safeguards

safeguard personal information

Protect personal information appropriate to its sensitivity, and guard against loss, theft, and unauthorised access, through measures like passwords, firewalls, and encryption for digital data, or locked filing cabinets and alarm systems for physical records.

8. Openness

Make your personal information management practices clear: a privacy policy outlining collection, use, disclosure, and security, that’s easy to understand and readily available to customers.

9. Individual Access

access to personal data

Customers have the right to access their personal information, and to challenge its accuracy and completeness. On request, disclose what information you hold, where it came from, who it’s been shared with, how it’s been used, and provide access at no or minimal cost, correcting errors and keeping records of any disputes.

10. Challenging Compliance

Individuals must be able to complain and challenge your compliance with these principles. Have complaint-handling procedures in place, inform complainants of their options, investigate every complaint, and improve your practices where needed. In Canada, privacy complaints can be filed with the Office of the Privacy Commissioner.

Conclusion

PIPEDA is similar to many privacy laws worldwide, balancing the need for data collection with individual rights. To comply, collect only the minimum personal information you need, obtain proper consent for collection, use, and disclosure, and be transparent about your practices.

If you run an online business, you’ll need a privacy policy disclosing what personal information you collect, how you use it, how it’s stored and secured, how long you retain it, and your contact details for any related concerns.

Generate your PIPEDA-compliant privacy policy today.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.