Privacy basics for Canadian businesses: PIPEDA, Law 25 and CASL
Published 2026-08-08 · Reviewed by Lawkin Editorial — pending independent legal review on 2026-08-11
This is legal information, not legal advice. It describes general rules that vary by province and by situation. A licensed lawyer must review your matter before you act on anything here.
Plain-English summary
Most Canadian businesses that handle customer information are subject to privacy legislation, including small ones. There is no general small-business exemption from the core obligations.
Three regimes come up most often:
PIPEDA — the federal private-sector privacy law, applying to personal information handled in commercial activity across Canada, except where a province has substantially similar legislation of its own.
Provincial privacy statutes — Alberta, British Columbia and Quebec have their own private-sector laws that apply instead of PIPEDA in many situations.
CASL — Canada's anti-spam legislation, governing commercial electronic messages. Separate from privacy law, and frequently overlooked.
Which applies depends substantially on where the individuals whose data you handle are located, not only on where your business sits.
What "personal information" covers
Broader than most businesses assume. It is information about an identifiable individual — not just names and email addresses, but anything that could identify someone alone or combined with other data, including device identifiers and behavioural records.
The practical test is whether an individual could reasonably be identified. Data a business thinks of as anonymous may still be regulated.
The core obligations
The details differ between statutes, but the shape is consistent:
Identify your purposes before or at collection, and limit use to those purposes. Using data for a new purpose generally needs fresh consent.
Obtain meaningful consent. The individual must reasonably understand what they are agreeing to. Sensitive information requires a higher standard, and Quebec's Law 25 requires express consent in more circumstances.
Limit collection to what is necessary for the identified purpose.
Safeguard the information with protection appropriate to its sensitivity.
Provide access. Individuals can generally request the personal information you hold about them.
Report breaches. Under PIPEDA, breaches creating a real risk of significant harm must be reported to the Privacy Commissioner and affected individuals as soon as feasible. Records must be kept of all breaches, not only reportable ones.
Quebec's Law 25 reaches further than many expect
Law 25 applies based on handling the personal information of people in Quebec, so a business elsewhere in Canada can be caught by it without any Quebec presence.
It goes beyond PIPEDA in several respects, including a requirement to designate a person responsible for privacy, privacy impact assessments in defined circumstances, express consent for sensitive information, and a right to data portability. Its maximum penalties are substantially higher.
CASL applies to ordinary business email
CASL is not only about bulk marketing. It governs commercial electronic messages generally, including routine business development email.
The requirements are consent — express or implied — clear identification of the sender, and a working unsubscribe mechanism honoured promptly. Implied consent categories are time-limited, which is where businesses most often drift out of compliance without noticing.
Key risks to watch
Assuming you are too small. The obligations attach to the activity, not to headcount.
Relying on a US-style privacy policy. A policy drafted for US or EU requirements will not map cleanly onto Canadian consent standards.
Treating breach response as an IT matter. Notification decisions have legal criteria and deadlines, and the record-keeping obligation applies to every breach.
Collecting because you might need it later. This runs directly against the limiting-collection principle and enlarges your exposure in a breach.
Losing track of where data goes. Using processors outside Canada is generally permitted, but it carries transparency obligations and requires appropriate contractual protection.
When to talk to a lawyer
Get advice if you handle sensitive personal information such as health or financial data, if you have customers in Quebec, if you transfer personal information outside Canada, or if you are responding to a breach — the last of these is time-sensitive and the criteria are legal rather than technical.
For a straightforward business collecting basic customer contact details, a properly drafted privacy policy and a documented approach to consent and retention will address most of the groundwork.