PIPEDA Compliance Checklist for Canadian SMBs (2026)
Updated June 2026 · Vendor-neutral guidance for Canadian businesses · Implementation by IT Cares
PIPEDA is Canada's federal private-sector privacy law. To comply, a small business must get meaningful consent to collect personal data, limit collection to a stated purpose, secure the data, honour access requests, appoint a privacy contact, and report breaches that pose a real risk of significant harm to the Privacy Commissioner.
What is PIPEDA and who must comply?
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law for private-sector organizations that collect, use, or disclose personal information in the course of commercial activity. It applies across most of Canada; provinces with "substantially similar" laws (Quebec, B.C., Alberta) apply their own for intra-provincial activity. There is no small-business exemption.
What are the 10 PIPEDA principles?
PIPEDA is built on ten fair-information principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. The checklist below turns these into concrete actions a small business can complete.
How does PIPEDA handle consent and collection?
You must obtain meaningful consent before collecting personal information, state the purpose clearly, and collect only what that purpose requires. Consent must be understandable to your audience — burying it in dense legalese can invalidate it. Let people withdraw consent, and stop collecting once the purpose is met.
What are PIPEDA's breach-reporting rules?
Since 2018, PIPEDA requires you to report any breach of security safeguards that creates a "real risk of significant harm" to the Office of the Privacy Commissioner of Canada and to notify affected individuals as soon as feasible. You must also keep records of all breaches, even minor ones, for 24 months.
How does PIPEDA overlap with Quebec's Law 25?
If you operate in Quebec, Law 25 governs your intra-provincial activity and is stricter than PIPEDA — it mandates a designated privacy officer, privacy-impact assessments, and carries heavier penalties (up to $25M or 4% of turnover). PIPEDA still applies to your interprovincial and international data flows. Build to the stricter standard and you cover both.
Key stat
PIPEDA breaches that pose a real risk of significant harm must be reported to the Privacy Commissioner, and breach records kept for 24 months. Quebec's Law 25 raises the ceiling further — penalties up to $25M or 4% of worldwide turnover.
At a glance
| Requirement | PIPEDA (federal) | Quebec Law 25 |
|---|---|---|
| Privacy officer | Accountable person required | Mandatory, named & published |
| Consent | Meaningful, purpose-limited | Explicit, stricter for sensitive data |
| Breach reporting | Real risk of significant harm | Real risk of serious injury |
| Privacy impact assessment | Recommended | Required for certain projects |
| Max penalty | Up to $100k (per offence) | Up to $25M or 4% of turnover |
Rather have it done for you? IT Cares can implement the technical safeguards PIPEDA requires.
FAQ
Does PIPEDA apply to small businesses?
Yes. PIPEDA applies to any private-sector organization that handles personal information for commercial activity, regardless of size. There is no small-business exemption.
What must a business do to comply with PIPEDA?
Get meaningful consent, limit collection to a stated purpose, secure the data, appoint a privacy contact, honour access requests, and report real-risk breaches to the Privacy Commissioner while keeping breach records for 24 months.
What's the difference between PIPEDA and Law 25?
PIPEDA is the federal baseline; Quebec's Law 25 is stricter — it mandates a named privacy officer, privacy-impact assessments, and far higher penalties. Build to Law 25 and you cover PIPEDA too.
What are the penalties for breaking PIPEDA?
PIPEDA fines reach up to $100,000 per offence for certain violations, plus reputational and remediation costs. In Quebec, Law 25 penalties can reach $25M or 4% of worldwide turnover.
Get a free IT & security assessment
Tell us where you are — we send back a clear, no-pressure plan. Leads only, no payment.