PIPEDA has no certificate. Prove it anyway.

The Personal Information Protection and Electronic Documents Act governs how private-sector organizations collect, use and disclose personal information in the course of commercial activity in Canada. There is no audit to pass and no badge to display, which is exactly why it gets deferred. What a regulator, an enterprise buyer or a breach actually asks for is evidence that you were operating the obligations all along.

Who it covers

  • It applies to you if: you handle the personal information of people in Canada during commercial activity - wherever your company is based. A US or UK SaaS with Canadian customers is in scope.
  • It also covers employee data: but only at federally regulated businesses: banks, telecoms, airlines, and interprovincial transport. Everyone else's employee data falls under provincial law.
  • Provincial laws can displace it: Alberta and British Columbia have their own substantially similar PIPAs, and Quebec's Law 25 is stricter. Those govern activity inside the province; PIPEDA still governs what crosses a border.

The ten fair information principles

  1. Accountability: Name someone accountable, make their identity available on request, and stay responsible for data you hand to a processor.
  2. Identifying Purposes: Document why you collect each piece of personal information, at or before you collect it.
  3. Consent: Meaningful, informed consent. Not bundled into terms of service, withdrawable at any time, and never obtained through deception.
  4. Limiting Collection: Collect only what the identified purpose needs, by fair and lawful means.
  5. Limiting Use, Disclosure, Retention: Use it only for what you collected it for, and keep it only as long as that purpose lasts. Retention schedules with real minimums and maximums.
  6. Accuracy: Keep personal information accurate and current enough that a decision made from it is not wrong.
  7. Safeguards: Protect it against loss, theft and unauthorized access, with physical, organizational and technological measures scaled to sensitivity. (automated evidence)
  8. Openness: Publish how you handle personal information, in plain language people can actually find.
  9. Individual Access: On written request, tell someone what you hold, how it was used and who it went to - within 30 days.
  10. Challenging Compliance: An accessible complaints procedure, every complaint investigated, and practices changed when a complaint is justified.

Breach obligations

  • Report to the Commissioner: Any breach creating a real risk of significant harm goes to the Office of the Privacy Commissioner as soon as feasible. Sensitivity of the data and probability of misuse are the deciding factors.
  • Notify the individuals: Directly and conspicuously, with enough detail that they can act to reduce their own risk. Indirect notification only where the rules allow it.
  • Tell other organizations: If another organization or a government institution could reduce the harm, they get told too.
  • Keep a register of every breach: For 24 months, whether or not it was reportable, producible to the Commissioner on request. This is the obligation companies most often discover they have never met.

What is actually automated

What we test automatically: Principle 7, Safeguards, and only Principle 7. Encryption in transit and at rest, multi-factor authentication, least-privilege access, network restriction, endpoint protection and secure disposal - continuously checked against your AWS, Azure, GCP, GitHub, Google Workspace, Okta and 20 other connected systems, with the evidence filed as it is collected.

What no software can prove: Consent, purposes, openness, individual access and complaints. A cloud API cannot tell you whether your consent was meaningful or whether you answered an access request in 30 days. Proofsteady tracks these as structured manual obligations with owners, evidence slots and dates - it does not pretend a firewall rule proves them.

That split is deliberate. Inflated automated coverage collapses the first time a regulator asks how a check evidences a consent clause, and an honest manual gap is worth more than a mapping that does not survive contact.

You have probably already built most of it

PIPEDA maps onto the same control layer as every other framework in Proofsteady, so a control you already operate counts toward it automatically. Control-area reuse, not a certification percentage.

  • 96% of PIPEDA's control areas are ones you already operate for SOC 2 (if your report included the optional Privacy criteria).
  • 79% of PIPEDA's control areas are ones you already operate for ISO 27001.
  • 64% of PIPEDA's control areas are ones you already operate for GDPR.

The SOC 2 figure carries a real condition: nearly all of that shared ground sits in SOC 2's Privacy (P-series) criteria, which are optional and left out of most SOC 2 reports. If your audit covered Security only, expect considerably less carry-over.

Questions, answered

Does PIPEDA apply to my company?

If you collect, use or disclose the personal information of people in Canada in the course of commercial activity, yes, regardless of where your company is based. A US or UK SaaS with Canadian customers is in scope. Alberta, British Columbia and Quebec have their own substantially similar private-sector laws that govern activity within those provinces, but PIPEDA still applies to personal information crossing a provincial or national border. Employee personal information is only covered at federally regulated businesses such as banks, telecoms and airlines.

Is there a PIPEDA certification?

No. PIPEDA is a law, not a certification, so there is no auditor to hire and no certificate to display. Compliance is an ongoing legal obligation demonstrated through evidence: your privacy policies, consent records, retention schedules, access-request handling and breach register. The Office of the Privacy Commissioner of Canada investigates on complaint or on its own initiative and publishes its findings, and matters can proceed to Federal Court. Anyone selling you a PIPEDA certificate is selling you their own opinion.

What are the PIPEDA breach reporting requirements?

Since 2018, any breach of security safeguards creating a real risk of significant harm must be reported to the Privacy Commissioner as soon as feasible, and the affected individuals must be notified directly with enough information to reduce their own risk. Other organizations that could mitigate the harm must be told as well. Separately, and this is the one most often missed, you must keep a record of EVERY breach for 24 months, whether or not it was reportable, and produce it to the Commissioner on request.

How is PIPEDA different from GDPR?

Both are privacy laws built on consent, purpose limitation, retention discipline and individual access, and about 64% of PIPEDA's control areas are ones you already operate for GDPR. The differences matter, though. PIPEDA runs on ten fair information principles rather than GDPR's six lawful bases, so consent does more of the work. Its breach threshold is a real risk of significant harm rather than a risk to rights and freedoms. And PIPEDA has no equivalent of GDPR's mandatory DPIAs, its international transfer regime, or fines up to 4% of global revenue.

How much of PIPEDA can be automated?

Less than any vendor's marketing implies, and being straight about that is the point. Of PIPEDA's 57 obligations, automated evidence genuinely exists for one principle: Safeguards. Encryption, access control, MFA, network restriction and endpoint protection are all continuously testable against your connected systems. Consent, identified purposes, openness, individual access and complaints are real obligations that no cloud API can evidence, so Proofsteady tracks them as structured manual work with owners and deadlines rather than inflating a coverage percentage.

Is PIPEDA being replaced?

Not yet. PIPEDA remains the operative federal private-sector privacy law. Bill C-27 died when Parliament was prorogued in January 2025, and Bill C-36, introduced in June 2026, would repeal Part 1 and replace it with the Protecting Privacy and Consumer Data Act. It is at first reading and is not law. Proofsteady tracks the statute rather than the headlines: our catalog records which consolidation it was built from, so you can see exactly what you are being measured against.