Personal Information Protection and Electronic Documents Act
Canadian federal privacy law governing how private sector organizations collect, use, and disclose personal information in commercial activities.
What PIPEDA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Safeguards
Personal information MUST be protected by security safeguards appropriate to the sensitivity of the information.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Individual Access
Upon request, individuals MUST be informed of the existence, use, and disclosure of their personal information.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
Breach Reporting
Organizations MUST report breaches that pose real risk of significant harm to the Privacy Commissioner and affected individuals.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Accountability
Organizations are ACCOUNTABLE for personal information under their control.
Governance requirements ask who is accountable and how they know. Role-based access lets auditors and risk owners see the evidence without touching the data, and scheduled reporting puts the same posture view in front of the people who have to sign. What the platform supplies is the substantiation behind the sign-off; naming the accountable owner remains yours.
What PIPEDA covers
s. 2(1)
Information about an identifiable individual, held in the course of commercial activity.
In scope
- Any factual or subjective information about an identifiable individual
- Employee information, for federal works and undertakings
What falls outside
Business contact information used solely to communicate with someone in relation to their employment or profession. That carve-out is narrower than it sounds and is a common source of over-confidence.
PIPEDA defines NO heightened category. Sensitivity is a factor in the reasonableness of safeguards under Principle 4.7, not a separate class of data — which is a real structural difference from GDPR and one that catches people migrating a GDPR programme north.
PIPEDA, S.C. 2000, c. 5 · as at 2026-08
How PIPEDA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Office of the Privacy Commissioner of Canada, with prosecution by the Crown.
| Published maximum | Charged | As at |
|---|---|---|
| CAD 100,000 | per offence, prosecuted rather than assessed | 2026-08 |
PIPEDA is deliberately weak on money next to the instruments beside it in this list. The Commissioner cannot levy administrative fines at all; the offence provisions cover obstructing an investigation and destroying records that are the subject of a request, and are prosecuted rather than assessed. Federal reform to change this died with Bill C-27 in January 2025.
The Commissioner has recommendation and reporting powers, not order-making powers. The practical exposure is reputational and, increasingly, a provincial one.
Uncapped exposure that sits outside this instrument
These come from company law rather than from PIPEDA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Directors’ duty of care
Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.
Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.
Who. Directors and officers personally.
The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.
Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for PIPEDA,
not configured for it afterwards
Canadian PII Access Monitoring
Track access to SIN, health card numbers, and Canadian identifiers
Access Request Response
Generate complete data access history for individual requests
Canadian PII Patterns
Detect SIN, provincial health numbers, Canadian postal codes
Breach Risk Detection
Identify access patterns that may constitute reportable breaches
Other Data Privacy frameworks
Walk into the PIPEDA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.