Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

Canadian Privacy Law for Small Businesses: PIPEDA and Quebec’s Law 25

Short answer: PIPEDA is Canada's federal private-sector privacy law, but Quebec, Alberta, and BC have their own general privacy laws. Quebec's Law 25, widely considered the strictest, requires a person in charge of personal information, a confidentiality incident register, and privacy impact assessments.

Canada doesn't have one privacy law for businesses — it has a federal one and, layered on top of it, three provinces with their own general private-sector laws (plus provincial health-privacy laws in some provinces). If your business collects a customer's name, email, phone number, or payment details anywhere in Canada, one of these applies to you, and if you're in Quebec, the rules got significantly stricter over the last few years. This post walks through both layers: the federal law (PIPEDA) that's the default almost everywhere in Canada, and Quebec's Law 25, which is widely considered the strictest private-sector privacy regime in the country.

The federal layer: PIPEDA

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law, and as of September 2026 it remains in force. (A federal replacement, Bill C-36, was tabled in June 2026 and is before Parliament; if it passes, its privacy rules would replace PIPEDA's. Until then, PIPEDA is the law.) It applies to private-sector organizations that collect, use, or disclose personal information in the course of a commercial activity — a deliberately broad definition covering any transaction, act, or regular course of conduct that's commercial in character. A shop selling products, a gym selling memberships, a contractor running a mailing list for past customers — all commercial activity. There's no size or revenue threshold. A two-person business is in scope on day one.

Here's the wrinkle that matters if you're anywhere in Canada: Quebec, Alberta, and British Columbia each have their own private-sector privacy law that the federal government has formally declared "substantially similar" to PIPEDA. For a business operating entirely within one of those three provinces — collecting, using, and disclosing personal information wholly inside that province — the provincial law applies instead of PIPEDA. The moment personal information crosses a provincial or national border (a Quebec business using a cloud vendor based in Ontario or the US, for example), PIPEDA comes back into play for that cross-border piece. PIPEDA also still applies in those three provinces to federally regulated businesses such as banks, telecoms, and airlines.

Elsewhere in Canada, PIPEDA is generally the private-sector law that applies, with one important exception: health information. Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia have health-privacy laws (Ontario's is PHIPA) that have also been declared substantially similar, so a clinic or other health information custodian in those provinces is generally governed by that provincial health law rather than PIPEDA for patient information.

PIPEDA's 10 fair information principles, in plain English

PIPEDA is built around ten principles, all listed as Schedule 1 of the Act. They're less a checklist and more a description of a business that handles personal information responsibly:

  1. Accountability — someone in the business is actually responsible for privacy compliance, by name, not "whoever gets to it."
  2. Identifying purposes — say why you're collecting information before or at the time you collect it, not after.
  3. Consent — get meaningful consent for collection, use, or disclosure, except in specific limited situations the law itself carves out.
  4. Limiting collection — collect only what you actually need for the stated purpose, not "everything, in case it's useful later."
  5. Limiting use, disclosure, and retention — use it only for the purpose it was collected for, and don't keep it longer than that purpose requires.
  6. Accuracy — keep the information as accurate, complete, and current as the intended use requires.
  7. Safeguards — protect it with security appropriate to how sensitive it is (a customer mailing list doesn't need the same protection as health or financial records).
  8. Openness — make your privacy practices — what you collect, why, and who's responsible — publicly available in plain language, not buried in a dense policy nobody reads.
  9. Individual access — a person can ask what personal information you hold about them and get a response, with limited exceptions.
  10. Challenging compliance — a person can complain about how their information was handled, and you have to have a process for that.

For a small business, this translates into concrete habits: know why you're collecting each field on your contact form, don't hoard customer records past the point they're useful, and have an actual, findable privacy policy — not a placeholder page nobody's updated since the site launched.

Mandatory breach reporting and record-keeping

Since PIPEDA's breach provisions came into force on November 1, 2018, organizations are required to:

"Significant harm" is defined broadly under the Act: it includes bodily harm, humiliation, damage to reputation, loss of employment or business opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property. Assessing the risk of that harm means weighing the sensitivity of the information involved and the probability it's been or will be misused — a lost laptop with an encrypted, password-protected customer database is a very different risk than the same laptop unencrypted. It's an offence to knowingly fail to report, notify, or keep the required breach records, and doing so can lead to fines.

The stricter layer: Quebec's Law 25

Quebec's Law 25 (formally An Act to modernize legislative provisions as regards the protection of personal information, which amended the province's existing private-sector law) rolled out in three phases and is now fully in force. If you're operating a business in Quebec, this — not PIPEDA — is very likely your primary obligation for anything that stays inside the province.

The person in charge of the protection of personal information

Every organization subject to the law must have a person in charge of the protection of personal information. Critically, this role isn't optional to assign — by default, it's the person exercising the highest authority in the organization (for most small businesses, the owner or CEO), unless that authority is formally delegated, in writing, to someone else. A five-person shop that has never thought about this already has a privacy officer: the owner, whether they know it or not. The title and contact information of whoever holds this role has to be published — customers need to be able to find out who to contact.

The confidentiality incident register and reporting to the CAI

Law 25 requires every organization to keep a register of confidentiality incidents. Like PIPEDA's breach record, it covers every incident, including ones that never rise to a reportable level, but Law 25's notion of a "confidentiality incident" is broader (it includes any unauthorized access, use, communication, or loss of personal information), and the register must be kept for at least five years, compared with PIPEDA's 24 months. It has to be produced to Quebec's privacy regulator, the Commission d'accès à l'information (CAI), on request. When an organization has reasonable grounds to believe a confidentiality incident presents a risk of serious injury to an affected person, it must promptly notify both the CAI and the affected individuals, with a notice whose required content (what happened, what information was involved, how many people were affected, what's being done about it) is itself set out in regulation.

Privacy impact assessments (PIAs)

Law 25 requires a privacy impact assessment at specific trigger points — for any project to acquire, develop, or overhaul an information system or electronic service delivery system that involves personal information, and before communicating personal information outside Quebec, including entrusting it to a service provider outside the province (which makes this relevant to almost any small business using a US-based cloud tool). The person in charge of personal information has to be consulted from the start of such a project. In practice, a PIA is worth revisiting whenever the project changes in a way that affects privacy risk.

Consent and transparency

Consent under Law 25 has to be clear, free, and informed, and it has to be requested for each specific purpose — not a blanket "we may use your information for any purpose" clause. When consent is requested in writing, the request has to be presented separately from any other information, not buried in general terms of service. Sensitive information (health data, biometric data, and similar categories) needs express consent before it's used for a purpose other than the one it was collected for, or shared with a third party. Businesses also have new transparency obligations: for example, telling people when a decision about them is based exclusively on automated processing, and letting them see the information and reasons used, have it corrected, and ask a person to review the decision.

Phased effective dates

Law 25 didn't arrive all at once:

Penalties — stated precisely

Law 25 introduced a two-track enforcement scheme that's considerably sharper than what existed before:

The percentage only raises the ceiling for large companies; for a small business the maximums are still the dollar figures. The CAI sets the amount of an administrative penalty based on the circumstances, and a court sets any penal fine on conviction. The CAI's power to impose administrative penalties took effect in September 2023. Law 25 also strengthened private lawsuits: where an infringement is intentional or results from gross fault, a court must award punitive damages of at least $1,000, separate from the regulator's own penalties.

A quick note on GDPR

If you've heard of the EU's GDPR and are wondering how it relates: GDPR is a separate law that, for a Canadian business with no establishment in the EU, only applies if it's actually offering goods or services to people in the EU, or monitoring their behaviour there. It's a deep enough topic for its own post; the short version here is don't confuse it with PIPEDA or Law 25 — they're independent obligations that can both apply to the same business.

Scenario: a Montreal home-services company treats "person in charge" as a formality

(This is a composite, illustrative scenario built from patterns that show up across small Quebec businesses adjusting to Law 25 — not a specific real company's story.)

A small Montreal-based home-services company — a dozen employees, an online booking form, and a CRM that stores customer names, addresses, phone numbers, and service history — heard about Law 25 secondhand, mostly through a line item on their software vendor's compliance page. The owner assumed "we'll deal with it if it ever comes up" and moved on.

Eighteen months later, a laptop used by a part-time scheduler is stolen from a parked car. The laptop had the CRM open in a browser tab with an active session — no separate password needed to see customer records. The business had never designated anyone as the person in charge of personal information protection in writing, so by law it defaulted to the owner, who had never been told that was now their formal legal responsibility. There was no confidentiality incident register to log the theft in, no documented process for deciding whether it met the "risk of serious injury" threshold for notifying the CAI, and no clear count of how many customer records were actually exposed, because nobody had ever mapped what the CRM held.

The company ended up building all of that under pressure: assessing the incident after the fact instead of through an existing process, notifying the CAI later than a business with a working register would have, individually contacting every customer whose information might have been exposed, and paying a consultant to help interpret obligations that would have taken a few hours to document calmly beforehand. In this scenario, no fine was issued, but the response cost weeks of the owner's time and a hit to customer trust that a five-minute written designation and a simple incident log would have avoided entirely.

What closing this gap actually looks like: put the person-in-charge designation in writing (even if it stays with the owner by default), start a simple confidentiality incident register before an incident happens, and require laptops and devices touching customer data to lock and require re-authentication — a stolen device with an active session is a much worse incident than a stolen device that's simply locked.

A note on what this is and isn't

This post is educational — a plain-English walkthrough written as I work through this material myself, not a substitute for reading the actual text of PIPEDA or Quebec's Act respecting the protection of personal information in the private sector, or for advice from a qualified privacy professional or lawyer about your specific business. It isn't legal advice, and it isn't a compliance assessment of your business. If any part of the scenario above sounds familiar, that's worth a direct conversation with a qualified professional, not just a blog post. Our free Compliance & Accessibility Self-Check is a general starting point for privacy basics, but it doesn't cover Canadian law specifically — for PIPEDA or Law 25, start with the source: the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.