PIPEDA in plain language: what Canadian business owners actually owe their customers
PIPEDA applies to most Canadian businesses that handle customer data. What the law requires, what enforcement looks like, and what it costs to comply.
The Office of the Privacy Commissioner of Canada closed 373 complaint investigations in the 2023-24 fiscal year, according to the OPC's annual report to Parliament. Most involved small and mid-sized businesses that had no idea they were on the hook until a customer complained.
Almost any Canadian business that collects customer data in the course of commercial activity falls under PIPEDA. A bakery with an email list. A contractor with a client database. A law firm running case files through an AI platform. The law is older than most of the tools businesses now use to comply with it, and that mismatch is where the confusion lives.
Four rules that do the work
PIPEDA rests on ten principles, borrowed from a 1996 model code and bolted onto federal law in 2000. Four of them handle almost everything a small business needs to worry about.
Consent comes first: a business needs a customer's knowledge and agreement to collect, use, or disclose personal information, with narrow exceptions for things like fraud investigation. Limiting collection is the second rule — gather only what a stated purpose actually requires, not everything a form could technically capture. Third, safeguards: personal information has to be protected with security "appropriate to the sensitivity" of the data. The Act doesn't specify encryption standards or vendor requirements, which is exactly why so many businesses guess wrong. Fourth is breach notification, added in 2018 under the Digital Privacy Act amendments. It requires reporting to the OPC and to affected individuals when a breach creates a "real risk of significant harm."
That last rule carries the sharpest teeth. Failure to report is itself an offence, separate from the breach itself. The OPC's breach reporting guidance spells out the threshold and the timeline, and it is worth twenty minutes of a business owner's time to read rather than assume.
A skeptical owner might point out that "real risk of significant harm" is a judgment call, not a bright line, and that's fair. The OPC's guidance lists factors — sensitivity of the information, probability it's been or will be misused — but leaves the weighing to the organization that had the breach. That ambiguity cuts both ways. It means a business can sometimes reasonably conclude a minor exposure doesn't clear the threshold. It also means a business that guesses wrong and stays quiet has no regulatory text to hide behind afterward. The OPC has been willing to treat under-reporting as the more serious problem, on the theory that a company deciding for itself what counts as low-risk is exactly the judgment the law was written to take out of its hands.
The Quebec carve-out
Quebec businesses operate under a stricter regime. Law 25, phased in through September 2023 and finished off with right-to-portability rules in September 2024, replaced the province's older private-sector privacy law. It added requirements PIPEDA doesn't have: mandatory privacy impact assessments for certain data projects, a named privacy officer by default, and specific rules on automated decision-making.
The Commission d'accès à l'information du Québec enforces Law 25 and can levy administrative penalties up to $10 million or 2% of worldwide turnover for a company, whichever is higher. That ceiling sits far above anything PIPEDA's current enforcement structure permits. A Quebec business handling customer data through an AI tool needs to satisfy both regimes at once, not pick one.
Transparency sits at the center of the CAI's guidance on Law 25: organizations must be clear with customers about how their personal information gets used. It reads as a simple line. In practice it is the one most businesses skip.
The privacy impact assessment is where that gets concrete, and where most owners underestimate the work. A PIA under Law 25 isn't a form filed once and forgotten — it has to happen before a new data project launches, cover what's collected, why, who it's shared with, and what happens if it crosses provincial or national borders. For a business adopting an AI tool that touches customer records, that means documenting the vendor's data flows specifically, not describing the business's general privacy posture. A firm that bought an AI platform without asking where inference happens is the firm that discovers, mid-assessment, that it can't answer the CAI's first question.
Enforcement, in dollars
PIPEDA itself doesn't carry the kind of administrative monetary penalties Law 25 does, at least not yet. Bill C-27, the federal government's proposed overhaul, would have introduced fines up to 5% of global revenue or $25 million for the most serious violations through a new Personal Information and Data Protection Tribunal. That bill died on the order paper when Parliament prorogued in January 2025. Its replacement hasn't been reintroduced in a form businesses can plan around.
What exists today is softer but not toothless. The OPC can name businesses publicly in its findings, negotiate compliance agreements, and refer matters to Federal Court, which can order damages. A search result showing a company under OPC investigation does more damage to a twelve-person firm than any fine currently on the books.
Quebec's $10-million ceiling next to the federal law's comparatively toothless enforcement is itself a policy story. Ottawa has been trying to close that gap since 2020 without success.
What that gap means in practice is that a business operating only outside Quebec is, for now, betting on reputational rather than financial consequence. That's a real distinction, not a technicality. A Federal Court referral takes years and produces a damages award tied to demonstrated harm, which is a high bar for a customer whose email address leaked but who can't show a dollar figure lost. A CAI penalty in Quebec doesn't require that showing. Two businesses with an identical breach, one in Toronto and one in Montreal, currently face meaningfully different downside — a gap that has nothing to do with how careless either one was.
Cheap now or expensive later
Compliance doesn't require a compliance officer on staff, and most small businesses don't have one. It requires a written privacy policy that matches what the business actually does. A designated person who owns privacy questions, even if that's a part-time responsibility. A data inventory listing what's collected and why. A breach response plan sketched out before it's needed rather than during a crisis. None of that costs meaningfully more than a few hours of a manager's time and, in some cases, a lawyer's review at a few hundred dollars.
Skipping that groundwork is what gets expensive. A breach nobody has a plan for. A customer complaint that turns into an OPC file. A Quebec engagement that skipped the privacy impact assessment Law 25 requires. Legal defense costs, notification costs to affected customers, and public OPC findings all add up faster than prevention would have.
The notification cost specifically tends to surprise owners who haven't priced it. Notifying affected individuals isn't a form email; the OPC's guidance expects direct notification unless the business can show that's impracticable, and for a customer list running into the thousands, that means a mail or email campaign, a call-center bump for the following weeks, and often a credit-monitoring offer if financial data was involved, all before any lawyer's invoice arrives. Businesses that priced this out after the fact, rather than before, describe it as the expense that made the earlier hours spent on a breach plan look cheap by comparison.
A growing number of Canadian businesses now run customer data, support tickets, contracts, HR records, through AI chat and document tools, often without checking where that data is processed or stored. A US-based AI tool routes data through American infrastructure, which brings it under the US CLOUD Act regardless of where the business itself is located. That complicates any Law 25 transfer assessment. A Canadian platform that keeps data storage in Canada sidesteps that particular exposure, not by promising compliance, but by removing one variable from the analysis.
Augure, a Vancouver-built AI platform, is one of a small number of options built around that distinction. Customer data is stored in Canada. Inference runs on Canadian infrastructure by default, with EU capacity as failover when Canadian capacity is unavailable, a detail worth disclosing to any business running its own Law 25 transfer assessment, since the comparison that matters is against US-hosted tools, not against a fictional standard of zero cross-border movement. No part of the stack sits under US jurisdiction: no US corporate parent, no US investors, no CLOUD Act exposure. None of that is a compliance guarantee. No vendor can offer one. But it changes what a business has to explain in its own privacy policy when a customer asks where their data goes.
Where this is heading
Bill C-27 is dead, but the pressure that produced it hasn't gone anywhere. Provincial regulators, particularly Quebec's CAI, have shown they'll enforce aggressively where federal law stays quiet, and other provinces are watching that model. A business that builds its privacy practice around PIPEDA's current, relatively permissive enforcement regime may find itself behind when federal reform actually passes.
Waiting for Ottawa isn't the move. Building the four basics is: consent, minimal collection, safeguards, breach readiness. Add vendors that don't pile cross-border complexity onto that picture, and the groundwork is mostly done.
More on how Augure handles data residency and Law 25/PIPEDA alignment is at augureai.ca.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.