← Back to Insights
Compliance Education

PIPEDA vs Law 25 vs Provincial Laws: Which One Actually Governs Your Business?

A practical account of figuring out which Canadian privacy law applies to a mid-size business, and what that meant for choosing a Canadian AI vendor.

By Augure·
grayscale photo of black and white wooden sign

The question that actually stalled us was not "which law applies" — it was "which law applies to which piece of data," because the honest answer turned out to be more than one, at the same time, for the same customer record.

That surprised me. I went in assuming this would resolve into a single answer, the way "what tax rate applies to us" resolves once you know your province and your revenue. Privacy law in Canada doesn't work that way. We're a mid-size services business with staff in two provinces and customers in most of them, and the answer we landed on was that PIPEDA, Quebec's Law 25, and at least one other provincial regime were all live simultaneously, each covering a different slice of what we do. If you're trying to figure out whether a Canadian AI tool, a new CRM, or anything touching customer data needs a compliance review, the jurisdictional question is the first thing to nail down, and it's genuinely not obvious — which is the whole reason I'm writing this up.

The federal default, and where it stops

PIPEDA — the Personal Information Protection and Electronic Documents Act — is the federal law and the default for any private-sector organization engaged in commercial activity, unless a province has passed something the federal government has declared "substantially similar." Quebec, British Columbia, and Alberta have all done that for at least parts of their private-sector activity. So the first fork in the road is: does your business operate somewhere with a substantially similar provincial law, and does that law cover the kind of activity you're doing.

We're headquartered outside Quebec, so I initially assumed PIPEDA was our whole world. It isn't. PIPEDA still governs any personal information that moves across a provincial or national border in the course of commercial activity, which meant that even with a Quebec-specific law in the picture, PIPEDA didn't fully step aside — it kept applying to the interprovincial parts of what we do. That was the first genuine surprise, and it's the kind of detail that gets glossed over in the "which law applies" explainers I read beforehand.

Why Law 25 mattered more than our headcount suggested

We have a small number of Quebec-based clients. Not our core market, maybe eight percent of active accounts. I initially treated that as a footnote — something our privacy lead would handle with an addendum, not something that would shape a vendor decision. That was wrong.

Law 25 (formerly Bill 64) applies to any organization that collects, holds, or uses personal information of Quebec residents, and it doesn't care how big that slice of your business is. It brought in mandatory breach notification to Quebec's data protection authority, a requirement for privacy impact assessments before certain projects go ahead, and — the part that actually changed our AI vendor shortlist — rules under section 17 about transferring personal information outside Quebec. If you're moving Quebec residents' data to a jurisdiction with weaker protections, you have to assess that transfer and document it.

Law 25 requires organizations to conduct a privacy impact assessment prior to a transfer of personal information outside Quebec if the personal information will serve to render a decision concerning an individual.

That single clause is why our privacy lead ended up in the room for what was originally an IT procurement conversation. Once eight percent of our data was Quebec-linked, the whole evaluation had to run at Law 25's standard, not PIPEDA's — running two separate compliance tracks for eight percent of records wasn't worth the overhead. Building for the stricter regime covers you for the looser one. My counsel's actual phrase, paraphrased because I didn't write it down verbatim, was something like: build to the higher bar and you don't have to keep asking which bar applies.

What we actually asked vendors

Once Law 25 was in scope, the vendor questions changed shape. We stopped asking generic security-review questions and started asking jurisdiction-specific ones. The list we used, roughly:

  • Where is customer data stored, physically, and can you name the country?
  • Where does inference or processing happen, and is any of it routed through US infrastructure?
  • Is our data used to train your models, ever?
  • If a foreign government compelled you to hand over data, what jurisdiction would that request come from, and does it reach us?
  • Can you support a breach notification timeline that meets Quebec's requirements, not just PIPEDA's?

Most of the US-based tools we looked at answered the first two questions fine and then got vague on the third and fourth. Not evasive exactly — I think the sales engineers genuinely didn't know, which is its own kind of answer.

The CLOUD Act point our counsel would not move on

This is the part that ended up mattering most, and it's narrower than people assume. The concern wasn't that a US vendor would misuse our data. It was that under the CLOUD Act, US-based providers can be compelled to produce data they control, regardless of where that data is physically stored, and a Canadian company's contractual promises don't override a US court order served on a US-jurisdiction parent company.

Our counsel's position was that any tool touching Quebec-linked personal information needed to sit entirely outside that jurisdictional reach for customer content specifically — not "encrypted in a way that helps," but structurally outside it. That's a narrower ask than most vendors are used to hearing, and it's where the shortlist actually shrank.

We evaluated Augure alongside two US-based platforms during this process. Augure's answer to the sub-processor question was concrete: customer data stored in Canada, inference running on Canadian infrastructure for some model tiers and with vetted EU partners under zero-retention agreements for others, and — this is the part that mattered to us — no US corporate parent and no US investors, so customer content and AI inference aren't handled by any provider a US court could reach through the CLOUD Act. Augure was upfront that email delivery and payment processing still touch US-based services, disclosed in the privacy policy rather than glossed over, and I actually preferred that over a vendor claiming zero US touchpoints anywhere, because that claim is almost never fully true and I'd rather work with someone who says so.

Pricing mattered less than I expected going in — Augure's team plan runs about C$80 a month per seat at the tier we needed, which was in the same range as the US alternatives, so cost didn't end up being the deciding factor. I'd flag that as the thing that turned out not to matter: we went into the evaluation assuming price would be the tiebreaker, and it wasn't close to the top three reasons we chose what we chose.

What I'd do differently

I would map the data before touching a single vendor question. We did it the other way around, starting vendor conversations before we'd fully confirmed which provinces our customer base actually touched, and had to redo two sub-processor conversations once the Law 25 exposure became clear. That cost us maybe a week we didn't need to lose.

I'm also not fully sure we've got the provincial layer right even now — Alberta's and BC's substantially similar legislation covers different activities than PIPEDA does in ways that I think still need a proper legal read, and we've flagged that as an open item rather than pretending we closed it. My privacy lead's honest assessment was that this gets revisited annually, not solved once.

If you're doing this exercise for the first time, the practical shortcut is to assume the strictest applicable law governs your whole dataset rather than trying to segment by province, because segmentation costs more in process than it saves in flexibility. A Canadian AI platform built for Law 25 and PIPEDA from the start rather than retrofitted removes at least one branch of that decision tree, though it doesn't remove the need to do the mapping in the first place. Augure's own pitch is that its architecture supports both regimes; it doesn't make the compliance determination for you, and no vendor honestly can.

More detail on how Augure handles data residency and the sub-processor list is at augureai.ca.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started