← Back to Insights
Compliance

Which Canadian Organizations Must Comply With PIPEDA

PIPEDA applies to almost every private-sector business in Canada that touches personal data. Here's who's covered, who's exempt, and what it means for AI tools.

By Augure Newsroom·
The British Columbia parliament buildings display the Canadian flag.

The Office of the Privacy Commissioner of Canada received 2,706 privacy breach reports in the 2023-2024 fiscal year, according to the OPC's reporting to Parliament. Almost every one of those reports came from an organization covered by the same federal statute: the Personal Information Protection and Electronic Documents Act, or PIPEDA. The gap between "we're a small shop, this doesn't apply to us" and the actual text of the act is where a lot of Canadian businesses get caught out.

PIPEDA covers private-sector organizations that collect, use, or disclose personal information in the course of commercial activity. That's the test. Not headcount, not revenue, not sector, with a few carve-outs described below. For any team now evaluating a Canadian AI platform to handle that data, the coverage question determines what the vendor contract needs to say.

Who's actually on the hook

The federal government's own guidance is direct on scope. Every organization engaged in commercial activity across Canada is covered, with three categories doing the heavy lifting:

  • Federally regulated businesses — banks, airlines, telecommunications companies, broadcasters — regardless of where in Canada they operate.
  • Private-sector organizations in provinces without their own "substantially similar" privacy law, which as of 2026 means most of the country outside Quebec, British Columbia, and Alberta.
  • Any organization, anywhere in Canada, when personal information crosses provincial or international borders.

That third category is the one people miss. A Quebec company operating entirely under Law 25 for its in-province customers is still subject to PIPEDA the moment it sends personal data to a payment processor in Ontario or a cloud vendor abroad. Provincial law and PIPEDA aren't mutually exclusive; they layer.

Nonprofits and political parties generally fall outside PIPEDA because they aren't engaged in commercial activity, though a nonprofit that sells merchandise or runs a paid membership program can trigger coverage for that slice of its operations.

The Quebec carve-out, and why it isn't really a carve-out

Quebec, British Columbia, and Alberta have each had their private-sector privacy laws declared "substantially similar" to PIPEDA, which means PIPEDA steps back for purely intra-provincial commercial activity in those jurisdictions. Quebec's version is Law 25 (formerly Bill 64), phased in through September 2023 and now among the toughest privacy regimes in the country, with penalties running up to 4% of worldwide turnover for the largest violations.

But "substantially similar" only covers activity that stays inside the province. A Montreal law firm using a document review tool hosted outside Quebec, or sharing client files with a partner office in Toronto, has just created a PIPEDA-relevant data flow on top of its Law 25 obligations. Federally regulated Quebec businesses — a Quebec-based airline, a Quebec-based bank branch — never left PIPEDA's jurisdiction in the first place.

"Organizations remain accountable for personal information under their control, including information that has been transferred to a third party for processing," the OPC has stated in its guidance on accountability.

That principle is the one that trips up procurement teams evaluating software vendors, including AI vendors. Handing data to a processor doesn't hand off the legal obligation.

Where AI tools complicate the compliance picture

Every one of the ten principles in PIPEDA's Schedule 1 — consent, limiting collection, safeguards, accountability — still applies when the third party doing the processing is a large language model rather than a payroll bureau. The complication is that a lot of AI tools in daily use by Canadian firms are American products, subject to the US CLOUD Act, which allows US law enforcement to compel American companies to produce data they control regardless of where that data is physically stored.

That's a genuine tension for an organization trying to satisfy PIPEDA's safeguard and accountability principles: it's difficult to represent to a client or regulator that data is adequately protected when the vendor holding it can be compelled by a foreign government to disclose it, independent of Canadian process. This is the gap that has pushed a wave of interest toward Canadian AI tools over the past two years — a straightforward reading of what accountability requires once a vendor contract is signed.

A handful of companies have built specifically toward this gap. Augure, a Montreal-founded AI platform, stores customer data in Canada and runs inference on Canadian infrastructure by default, with EU capacity as failover rather than US infrastructure. The company says it has no US corporate parent and no US investors, which it argues puts its stack outside US jurisdiction and CLOUD Act exposure — a distinction that matters for the safeguards analysis PIPEDA requires and, for Quebec-based firms, for the cross-border transfer assessment under Law 25. Where EU failover is relevant to that transfer analysis, the honest move is to say so rather than imply everything stays in Canada; Augure discloses the EU failover rather than describing all processing as domestic. Other Canadian AI platforms are making similar architectural arguments, and procurement teams are increasingly asking vendors to document exactly where inference happens, not just where the marketing copy says it happens.

What compliance actually requires in practice

PIPEDA doesn't hand out compliance certificates, and no vendor, Augure included, can promise that using a given platform satisfies the act on an organization's behalf. What the law asks for is a set of practices: meaningful consent before collection, use limited to a stated purpose, reasonable safeguards, and a designated person accountable for the whole chain, including whatever third-party processors touch that data.

For an organization sizing up whether an AI chat tool, a document Q&A system, or a contract-review product fits inside that framework, the questions are concrete. Where does inference run. Is customer data used to train the underlying model. What happens to a document uploaded for review once the session ends. A law firm using an AI contract-review tool to triage NDAs is disclosing client personal information to that vendor and needs an answer to all three questions before the contract gets signed, not after a breach report gets filed with the OPC.

Federal reform has been circling this file for a while. Bill C-27, which would have replaced PIPEDA's consumer-privacy provisions with the Consumer Privacy Protection Act and introduced a new AI-specific statute, died on the order paper when Parliament prorogued in January 2025. PIPEDA remains the operative federal law as of this writing, and whatever eventually replaces it is unlikely to loosen the accountability principle already causing the AI-vendor headaches described above.

Where this leaves procurement teams

None of this is exotic. It's the same due-diligence exercise Canadian compliance officers have run on outsourced payroll and cloud storage for two decades, applied to a newer category of vendor. The organizations most exposed right now are the ones that adopted a consumer AI chatbot for internal work — drafting, summarizing client files, triaging correspondence — without ever running it through the vendor-risk process a payroll provider would have triggered automatically.

Augure's own documentation, alongside the OPC's guidance on accountability and the CAI's published material on Law 25, is a reasonable starting point for anyone doing that review this quarter.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started