Skip to main content
All glossary terms
Legal & RegulatoryGlossary

PIPEDA

Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information in commercial activities.

Reference definitionAll

What PIPEDA means

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal privacy law governing commercial private-sector data practices. It applies to organizations that collect, use, or disclose personal information in the course of commercial activity. PIPEDA is built on 10 fair information principles including accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. For advertisers targeting Canadian users, PIPEDA requires meaningful consent for data collection, limits data use to stated purposes, and provides individuals with access to their data. Provincial privacy laws in British Columbia, Alberta, and Quebec may also apply. Quebec's Law 25 (modernized in 2023) is particularly stringent, with GDPR-like consent requirements and significant penalties. PIPEDA works alongside CASL for electronic marketing communications.

Related terms

Related Resources