Privacy is no longer a legal page you add before launch. For anything that collects names, emails, locations, payments or health details, privacy requirements shape the product itself: what you collect, how consent works, where data lives and what happens when something goes wrong.
This guide summarizes what Canadian privacy law expects from teams building apps and websites in 2026, and ends with a checklist you can hand to your product team.
Which privacy laws apply to your app?
PIPEDA covers private-sector organizations that collect, use or disclose personal information in the course of commercial activity. Federally regulated businesses (banks, airlines, telecoms) are always covered, and so is personal information that crosses provincial or national borders.
Three provinces have private-sector laws deemed substantially similar to PIPEDA, which apply to activity within those provinces:
| Law | Who it covers | What stands out for app builders |
|---|---|---|
| PIPEDA (federal) | Commercial activity across Canada, including Ontario | 10 fair information principles, meaningful consent, mandatory breach reporting |
| Quebec Law 25 | Organizations handling personal information in Quebec | Privacy officer, privacy by default, privacy impact assessments, portability, large penalties |
| Alberta PIPA | Private-sector organizations in Alberta | Breach notification to the Commissioner when there's a real risk of significant harm |
| BC PIPA | Corporations, non-profits, charities and unions in BC | Breach reporting is recommended but not yet mandatory |
| Ontario PHIPA | Health information custodians in Ontario | Fines up to $1M and administrative penalties up to $500,000 for organizations |
Ontario has no general private-sector privacy law, so Ontario businesses fall under PIPEDA, with PHIPA layered on top for health information custodians.
PIPEDA's 10 principles, translated for product teams
PIPEDA is built on ten fair information principles. Here is what each one means when you're designing software:
- Accountability — someone owns privacy, and you can show your practices.
- Identifying purposes — know why you collect each field before you add it to a form.
- Consent — get meaningful consent for collection, use and disclosure.
- Limiting collection — collect only what those purposes need.
- Limiting use, disclosure and retention — don't repurpose data, and delete it when you no longer need it.
- Accuracy — keep information accurate enough for its purpose.
- Safeguards — protect data with security appropriate to its sensitivity.
- Openness — publish clear information about your practices.
- Individual access — let people see, and correct, what you hold about them.
- Challenging compliance — give people a way to complain and get an answer.
Consent that actually counts
The Office of the Privacy Commissioner (OPC) expects consent to be meaningful. Its guidelines emphasize seven principles — from putting key information up front to treating consent as an ongoing process — and four elements every privacy notice should make prominent:
- what personal information is collected;
- who it will be shared with;
- why it's collected (the purposes);
- the risks of harm or other consequences.
Express consent is generally needed when information is sensitive, when a use falls outside what people would reasonably expect, or when it creates a meaningful risk of significant harm. You also need to offer a clear choice for any collection that isn't necessary to provide the service, and seek consent again when your practices change significantly. For children under 13, the OPC expects parental consent in all but exceptional cases.
Quebec's Law 25: the strictest rules in Canada
If you have users in Quebec, Law 25 raises the bar well above PIPEDA. Its obligations came into force in three phases between 2022 and 2024:
- A person in charge of privacy. By default it's the organization's highest authority, who can delegate in writing. Their title and contact details must be published on your website.
- Privacy by default. Privacy settings must default to the highest level of confidentiality (browser cookies are excluded from this rule). Functions that identify, locate or profile people must be off by default, and people must be told about them in advance.
- Consent. Sensitive information needs express consent, and consent requests must be presented separately, in clear and simple terms. Minors under 14 need consent from a parent or tutor.
- Automated decisions. If a decision about someone is made exclusively by automated processing, you must tell them, and on request explain the factors used.
- Transfers outside Quebec. A privacy impact assessment is required first, information can leave only if it will be adequately protected, and a written agreement is needed.
- Portability. Since September 22, 2024, people can request their information in a structured, commonly used technological format.
- Penalties. Administrative monetary penalties reach $10M or 2% of worldwide turnover, and penal fines reach $25M or 4% — whichever is greater.
Breach readiness is a feature
Under PIPEDA, if a breach of security safeguards creates a real risk of significant harm — humiliation, damage to reputation, financial loss, identity theft and more — you must report it to the OPC and notify affected individuals as soon as feasible. You must also keep a record of every breach for 24 months, reportable or not. Knowingly failing to report or keep records can lead to fines of up to $100,000.
Quebec requires confidentiality incidents with a risk of serious injury to be reported to its regulator, the Commission d'accès à l'information, and every organization must keep an incident register.
In product terms, that means logging and alerting good enough to detect incidents, access logs that show what was exposed, and a response plan your team has rehearsed.
Sending data outside Canada
Using a US cloud provider or an overseas development partner is allowed. PIPEDA has no general data-residency requirement. But the transferring organization stays accountable. You must protect the information through contracts or other means that provide a comparable level of protection, and tell people — ideally when you collect their data — that it may be processed in another country and accessed by authorities there.
Quebec goes further: a privacy impact assessment and a written agreement come before information leaves the province. The OPC also has draft guidance on assessing third-party service providers, open for comment until December 4, 2026.
Email sign-ups and CASL
Canada's Anti-Spam Legislation applies to commercial electronic messages. For newsletter and marketing sign-ups:
- Express consent must be opt-in. No pre-checked boxes; silence isn't consent.
- Ask separately from your terms and conditions, identify who is asking, give contact details, and say consent can be withdrawn.
- Keep proof of consent.
- Implied consent from an existing business relationship lasts 2 years after a purchase or 6 months after an inquiry.
- Process unsubscribe requests within 10 business days, at no cost.
Administrative penalties reach $10M per violation for businesses.
What Bill C-36 would change
After Bill C-27 died on the Order Paper in January 2025, the federal government tabled Bill C-36, the Protecting Privacy and Consumer Data Act, on June 15, 2026. As of late September 2026 it has only completed first reading. If passed in its current form, it would:
- replace Part 1 of PIPEDA with a standalone privacy law;
- require a formal privacy management program;
- add consent exceptions for "business activities" and "legitimate interest" — but not where the purpose is to influence a person's behaviour or decisions;
- require a privacy impact assessment before transferring information outside Canada;
- treat children's information (under 18) as sensitive, with a "best interests of the child" duty;
- create rights to deletion and data mobility, plus transparency for automated decision systems;
- introduce administrative penalties of up to the greater of $10M or 3% of global revenue, fines up to $25M or 5%, and a private right of action;
- move enforcement to a new Digital Safety and Data Protection Commission of Canada.
A privacy-by-design checklist for your next app
Use this list in discovery and again before launch:
- Map the data. For every personal field: what it is, why you need it, where it's stored and who can access it.
- Collect less. Remove fields that don't serve an identified purpose.
- Unbundle consent. Separate required processing from optional uses such as marketing or analytics.
- Default to private. Most-private settings by default; location and profiling off until the user opts in.
- Protect it. Encryption in transit and at rest, least-privilege access, MFA for admin tools.
- Set retention rules and build deletion into the product — not into a spreadsheet of reminders.
- Support rights requests. Access, correction and (for Quebec) portability in a structured format.
- Vet vendors. Contracts with every processor, and a cross-border notice in your privacy policy.
- Be breach-ready. Detection, an incident register kept for at least 24 months, and a tested response plan.
- Explain automated decisions wherever software, not a person, makes the call.
- Publish a clear privacy policy that names your privacy officer.
- Check CASL on every form that leads to marketing emails.
Sources
- Office of the Privacy Commissioner of Canada — PIPEDA in brief and Guidelines for obtaining meaningful consent
- PIPEDA, sections 10.1–10.3 and 28 (breach reporting, records and offences)
- OPC — Guidelines for processing personal data across borders
- Quebec's Act respecting the protection of personal information in the private sector and the CAI's summary of Law 25
- Information and Privacy Commissioner of Ontario — PHIPA
- CRTC — CASL FAQ
- Parliament of Canada — Bill C-36 on LEGISinfo and Government of Canada announcement



