Legal obligation
Personal Information Protection and Electronic Documents Act (PIPEDA)
Personal Information Protection and Electronic Documents Act (PIPEDA) — legal obligation, Federal (Canada). It binds organisations that collect, use or disclose personal information in the course of commercial activity, and federally regulated employers with respect to their employees' personal information.
- Jurisdiction
- Federal (Canada)
- Record class
- Legal obligation
- Instrument
- Reporting
- Last verified
Where this applies
This record is scoped to Federal (Canada). Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, Part 1
Who it binds
Organisations that collect, use or disclose personal information in the course of commercial activity, and federally regulated employers with respect to their employees' personal information.
What it requires
PIPEDA sets the federal rules for how organisations handle personal information in commercial activity, overseen by the Office of the Privacy Commissioner of Canada (OPC). It does not apply everywhere in Canada without qualification: some provinces have their own private-sector privacy law that applies instead within that province for provincially regulated activity — Québec's own law is a confirmed example (see the separate Québec record). Cross-border data transfers and federally regulated businesses remain under PIPEDA regardless.
Route to the authority
Last verified:
Related records and requirements
- Technology and Data — Applies if you collect, use or disclose personal information in the course of commercial activity.
- Finance and Professional Services — Applies if you collect, use or disclose personal information in the course of commercial activity.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's own private-sector privacy law is the general-compliance regime for private-sector businesses handling personal information within Québec — it takes the place of PIPEDA for that in-province activity.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — The Privacy Act 1988 binds Australian government agencies and covered organisations to 13 Australian Privacy Principles — the small-business turnover exemption has documented exceptions.
- Act on the Protection of Personal Information (APPI) compliance (Japan) — APPI's general obligations (Art. 21(1) purpose notification, Art. 23 security-management measures) bind business operators handling personal information in Japan.
- Personal Data (Privacy) Ordinance compliance (Hong Kong SAR China) — Hong Kong's Cap. 486 sets six Data Protection Principles binding data users in Hong Kong, overseen by the PCPD.
- Personal data protection compliance (Vietnam) — Vietnam's Decree 13/2023 and, from 1 January 2026, Law 91/2025 bind organisations processing personal data in Vietnam to a general data-protection compliance regime.
- Federal personal data protection compliance (Mexico) — Mexico's federal private-sector data-protection law, replaced in full on 20 March 2025, binds private-sector personal-data processing nationwide.
- Personal Data Protection Law (PDPL) compliance (Saudi Arabia) — Saudi Arabia's PDPL (Royal Decree M/19) binds entities processing personal data in Saudi Arabia to a general data-protection compliance law.
- Federal personal data protection compliance (United Arab Emirates) — The UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) binds organisations processing personal data inside or outside the UAE where the processing relates to the UAE — separate from DIFC's and ADGM's own free-zone regimes.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.