Skip to content
Security & Compliance

Privacy Compliance for Apps in Canada: A 2026 Checklist (PIPEDA, Law 25 & Bill C-36)

What PIPEDA, Quebec's Law 25, provincial laws and CASL require when you build an app or website in Canada — plus what the proposed Bill C-36 would change.

NPCoding TeamPublished 7 min read
A padlock on a laptop keyboard surrounded by light trails

Privacy is no longer a legal page you add before launch. For anything that collects names, emails, locations, payments or health details, privacy requirements shape the product itself: what you collect, how consent works, where data lives and what happens when something goes wrong.

This guide summarizes what Canadian privacy law expects from teams building apps and websites in 2026, and ends with a checklist you can hand to your product team.

Which privacy laws apply to your app?

PIPEDA covers private-sector organizations that collect, use or disclose personal information in the course of commercial activity. Federally regulated businesses (banks, airlines, telecoms) are always covered, and so is personal information that crosses provincial or national borders.

Three provinces have private-sector laws deemed substantially similar to PIPEDA, which apply to activity within those provinces:

LawWho it coversWhat stands out for app builders
PIPEDA (federal)Commercial activity across Canada, including Ontario10 fair information principles, meaningful consent, mandatory breach reporting
Quebec Law 25Organizations handling personal information in QuebecPrivacy officer, privacy by default, privacy impact assessments, portability, large penalties
Alberta PIPAPrivate-sector organizations in AlbertaBreach notification to the Commissioner when there's a real risk of significant harm
BC PIPACorporations, non-profits, charities and unions in BCBreach reporting is recommended but not yet mandatory
Ontario PHIPAHealth information custodians in OntarioFines up to $1M and administrative penalties up to $500,000 for organizations

Ontario has no general private-sector privacy law, so Ontario businesses fall under PIPEDA, with PHIPA layered on top for health information custodians.

PIPEDA's 10 principles, translated for product teams

PIPEDA is built on ten fair information principles. Here is what each one means when you're designing software:

  1. Accountability — someone owns privacy, and you can show your practices.
  2. Identifying purposes — know why you collect each field before you add it to a form.
  3. Consent — get meaningful consent for collection, use and disclosure.
  4. Limiting collection — collect only what those purposes need.
  5. Limiting use, disclosure and retention — don't repurpose data, and delete it when you no longer need it.
  6. Accuracy — keep information accurate enough for its purpose.
  7. Safeguards — protect data with security appropriate to its sensitivity.
  8. Openness — publish clear information about your practices.
  9. Individual access — let people see, and correct, what you hold about them.
  10. Challenging compliance — give people a way to complain and get an answer.

The Office of the Privacy Commissioner (OPC) expects consent to be meaningful. Its guidelines emphasize seven principles — from putting key information up front to treating consent as an ongoing process — and four elements every privacy notice should make prominent:

  • what personal information is collected;
  • who it will be shared with;
  • why it's collected (the purposes);
  • the risks of harm or other consequences.

Express consent is generally needed when information is sensitive, when a use falls outside what people would reasonably expect, or when it creates a meaningful risk of significant harm. You also need to offer a clear choice for any collection that isn't necessary to provide the service, and seek consent again when your practices change significantly. For children under 13, the OPC expects parental consent in all but exceptional cases.

Quebec's Law 25: the strictest rules in Canada

If you have users in Quebec, Law 25 raises the bar well above PIPEDA. Its obligations came into force in three phases between 2022 and 2024:

  • A person in charge of privacy. By default it's the organization's highest authority, who can delegate in writing. Their title and contact details must be published on your website.
  • Privacy by default. Privacy settings must default to the highest level of confidentiality (browser cookies are excluded from this rule). Functions that identify, locate or profile people must be off by default, and people must be told about them in advance.
  • Consent. Sensitive information needs express consent, and consent requests must be presented separately, in clear and simple terms. Minors under 14 need consent from a parent or tutor.
  • Automated decisions. If a decision about someone is made exclusively by automated processing, you must tell them, and on request explain the factors used.
  • Transfers outside Quebec. A privacy impact assessment is required first, information can leave only if it will be adequately protected, and a written agreement is needed.
  • Portability. Since September 22, 2024, people can request their information in a structured, commonly used technological format.
  • Penalties. Administrative monetary penalties reach $10M or 2% of worldwide turnover, and penal fines reach $25M or 4% — whichever is greater.

Breach readiness is a feature

Under PIPEDA, if a breach of security safeguards creates a real risk of significant harm — humiliation, damage to reputation, financial loss, identity theft and more — you must report it to the OPC and notify affected individuals as soon as feasible. You must also keep a record of every breach for 24 months, reportable or not. Knowingly failing to report or keep records can lead to fines of up to $100,000.

Quebec requires confidentiality incidents with a risk of serious injury to be reported to its regulator, the Commission d'accès à l'information, and every organization must keep an incident register.

In product terms, that means logging and alerting good enough to detect incidents, access logs that show what was exposed, and a response plan your team has rehearsed.

Sending data outside Canada

Using a US cloud provider or an overseas development partner is allowed. PIPEDA has no general data-residency requirement. But the transferring organization stays accountable. You must protect the information through contracts or other means that provide a comparable level of protection, and tell people — ideally when you collect their data — that it may be processed in another country and accessed by authorities there.

Quebec goes further: a privacy impact assessment and a written agreement come before information leaves the province. The OPC also has draft guidance on assessing third-party service providers, open for comment until December 4, 2026.

Email sign-ups and CASL

Canada's Anti-Spam Legislation applies to commercial electronic messages. For newsletter and marketing sign-ups:

  • Express consent must be opt-in. No pre-checked boxes; silence isn't consent.
  • Ask separately from your terms and conditions, identify who is asking, give contact details, and say consent can be withdrawn.
  • Keep proof of consent.
  • Implied consent from an existing business relationship lasts 2 years after a purchase or 6 months after an inquiry.
  • Process unsubscribe requests within 10 business days, at no cost.

Administrative penalties reach $10M per violation for businesses.

What Bill C-36 would change

After Bill C-27 died on the Order Paper in January 2025, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act, on June 15, 2026. As of late September 2026 it has only completed first reading. If passed in its current form, it would:

  • replace Part 1 of PIPEDA with a standalone privacy law;
  • require a formal privacy management program;
  • add consent exceptions for "business activities" and "legitimate interest" — but not where the purpose is to influence a person's behaviour or decisions;
  • require a privacy impact assessment before transferring information outside Canada;
  • treat children's information (under 18) as sensitive, with a "best interests of the child" duty;
  • create rights to deletion and data mobility, plus transparency for automated decision systems;
  • introduce administrative penalties of up to the greater of $10M or 3% of global revenue, fines up to $25M or 5%, and a private right of action;
  • move enforcement to a new Digital Safety and Data Protection Commission of Canada.

A privacy-by-design checklist for your next app

Use this list in discovery and again before launch:

  1. Map the data. For every personal field: what it is, why you need it, where it's stored and who can access it.
  2. Collect less. Remove fields that don't serve an identified purpose.
  3. Unbundle consent. Separate required processing from optional uses such as marketing or analytics.
  4. Default to private. Most-private settings by default; location and profiling off until the user opts in.
  5. Protect it. Encryption in transit and at rest, least-privilege access, MFA for admin tools.
  6. Set retention rules and build deletion into the product — not into a spreadsheet of reminders.
  7. Support rights requests. Access, correction and (for Quebec) portability in a structured format.
  8. Vet vendors. Contracts with every processor, and a cross-border notice in your privacy policy.
  9. Be breach-ready. Detection, an incident register kept for at least 24 months, and a tested response plan.
  10. Explain automated decisions wherever software, not a person, makes the call.
  11. Publish a clear privacy policy that names your privacy officer.
  12. Check CASL on every form that leads to marketing emails.

Sources

Frequently asked questions

Does PIPEDA apply to my Ontario business?

Most likely. Ontario has no general private-sector privacy law, so PIPEDA applies to Ontario organizations that collect, use or disclose personal information in the course of commercial activity. Health information custodians in Ontario are also covered by PHIPA.

Does Canadian law require personal data to stay in Canada?

PIPEDA has no general data-residency requirement. You can use service providers abroad, but you remain accountable: protect the data by contract and tell individuals their information may be processed outside Canada. Quebec's Law 25 adds a privacy impact assessment before information leaves Quebec.

Is Bill C-36 law yet?

No. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, was tabled on June 15, 2026 and, as of late September 2026, had only completed first reading. Its details can still change before it passes.

What counts as valid consent for marketing emails in Canada?

Under CASL, express consent must be opt-in: no pre-checked boxes, requested separately from terms and conditions, identifying who is asking, and stating that consent can be withdrawn. Unsubscribe requests must be processed within 10 business days.

  • #pipeda
  • #law-25
  • #privacy
  • #casl
  • #bill-c-36

Insights