# Privacy Compliance for Apps in Canada: A 2026 Checklist (PIPEDA, Law 25 & Bill C-36)

> What PIPEDA, Quebec's Law 25, provincial laws and CASL require when you build an app or website in Canada — plus what the proposed Bill C-36 would change.

Source: https://npcoding.ca/blog/pipeda-privacy-compliance-app-development-canada/
Last updated: 2026-09-22

By NPCoding Team · Published 2026-09-22 · Security & Compliance · 7 min read

Privacy is no longer a legal page you add before launch. For anything that collects names, emails, locations, payments or health details, **privacy requirements shape the product itself**: what you collect, how consent works, where data lives and what happens when something goes wrong.

This guide summarizes what Canadian privacy law expects from teams building apps and websites in 2026, and ends with a checklist you can hand to your product team.

> **Not legal advice**
>
> This article is general information for product and engineering teams, current as of September 2026. For decisions about your organization, work with qualified privacy counsel.

**Key takeaways**

- PIPEDA applies to most private-sector organizations in Canada. Alberta, BC and Quebec have their own substantially similar laws.
- Quebec’s Law 25 is the strictest regime today: privacy by default, privacy impact assessments for transfers outside Quebec and penalties of up to $25M or 4% of worldwide turnover.
- Breaches that create a real risk of significant harm must be reported, and every breach must be recorded for 24 months.
- CASL governs your email sign-up forms: opt-in only, never pre-checked.
- Bill C-36 would replace Part 1 of PIPEDA, but as of September 2026 it is only a proposal.

## Which privacy laws apply to your app?

**PIPEDA** covers private-sector organizations that collect, use or disclose personal information in the course of commercial activity. Federally regulated businesses (banks, airlines, telecoms) are always covered, and so is personal information that crosses provincial or national borders.

Three provinces have private-sector laws deemed *substantially similar* to PIPEDA, which apply to activity within those provinces:

| Law | Who it covers | What stands out for app builders |
| --- | --- | --- |
| **PIPEDA** (federal) | Commercial activity across Canada, including Ontario | 10 fair information principles, meaningful consent, mandatory breach reporting |
| **Quebec Law 25** | Organizations handling personal information in Quebec | Privacy officer, privacy by default, privacy impact assessments, portability, large penalties |
| **Alberta PIPA** | Private-sector organizations in Alberta | Breach notification to the Commissioner when there's a real risk of significant harm |
| **BC PIPA** | Corporations, non-profits, charities and unions in BC | Breach reporting is recommended but not yet mandatory |
| **Ontario PHIPA** | Health information custodians in Ontario | Fines up to $1M and administrative penalties up to $500,000 for organizations |

Ontario has no general private-sector privacy law, so **Ontario businesses fall under PIPEDA**, with PHIPA layered on top for health information custodians.

## PIPEDA's 10 principles, translated for product teams

PIPEDA is built on ten fair information principles. Here is what each one means when you're designing software:

1. **Accountability** — someone owns privacy, and you can show your practices.
2. **Identifying purposes** — know *why* you collect each field before you add it to a form.
3. **Consent** — get meaningful consent for collection, use and disclosure.
4. **Limiting collection** — collect only what those purposes need.
5. **Limiting use, disclosure and retention** — don't repurpose data, and delete it when you no longer need it.
6. **Accuracy** — keep information accurate enough for its purpose.
7. **Safeguards** — protect data with security appropriate to its sensitivity.
8. **Openness** — publish clear information about your practices.
9. **Individual access** — let people see, and correct, what you hold about them.
10. **Challenging compliance** — give people a way to complain and get an answer.

## Consent that actually counts

The Office of the Privacy Commissioner (OPC) expects consent to be *meaningful*. Its guidelines emphasize seven principles — from putting key information up front to treating consent as an ongoing process — and four elements every privacy notice should make prominent:

- **what** personal information is collected;
- **who** it will be shared with;
- **why** it's collected (the purposes);
- the **risks of harm** or other consequences.

**Express consent** is generally needed when information is sensitive, when a use falls outside what people would reasonably expect, or when it creates a meaningful risk of significant harm. You also need to offer a clear choice for any collection that isn't necessary to provide the service, and seek consent again when your practices change significantly. For **children under 13**, the OPC expects parental consent in all but exceptional cases.

> **Design pattern**
>
> Unbundle consent. A checkbox that bundles "terms, privacy policy and marketing" into one click fails several of these expectations at once. Separate what's required for the service from what's optional.

## Quebec's Law 25: the strictest rules in Canada

If you have users in Quebec, Law 25 raises the bar well above PIPEDA. Its obligations came into force in three phases between 2022 and 2024:

- **A person in charge of privacy.** By default it's the organization's highest authority, who can delegate in writing. Their title and contact details must be published on your website.
- **Privacy by default.** Privacy settings must default to the highest level of confidentiality (browser cookies are excluded from this rule). Functions that identify, locate or profile people must be off by default, and people must be told about them in advance.
- **Consent.** Sensitive information needs express consent, and consent requests must be presented separately, in clear and simple terms. Minors under 14 need consent from a parent or tutor.
- **Automated decisions.** If a decision about someone is made exclusively by automated processing, you must tell them, and on request explain the factors used.
- **Transfers outside Quebec.** A privacy impact assessment is required first, information can leave only if it will be adequately protected, and a written agreement is needed.
- **Portability.** Since September 22, 2024, people can request their information in a structured, commonly used technological format.
- **Penalties.** Administrative monetary penalties reach $10M or 2% of worldwide turnover, and penal fines reach $25M or 4% — whichever is greater.

## Breach readiness is a feature

Under PIPEDA, if a breach of security safeguards creates a **real risk of significant harm** — humiliation, damage to reputation, financial loss, identity theft and more — you must **report it to the OPC and notify affected individuals as soon as feasible**. You must also **keep a record of every breach for 24 months**, reportable or not. Knowingly failing to report or keep records can lead to fines of up to $100,000.

Quebec requires confidentiality incidents with a *risk of serious injury* to be reported to its regulator, the Commission d'accès à l'information, and every organization must keep an incident register.

In product terms, that means logging and alerting good enough to detect incidents, access logs that show *what* was exposed, and a response plan your team has rehearsed.

## Sending data outside Canada

Using a US cloud provider or an overseas development partner is allowed. **PIPEDA has no general data-residency requirement.** But the transferring organization stays accountable. You must protect the information through contracts or other means that provide a *comparable level of protection*, and tell people — ideally when you collect their data — that it may be processed in another country and accessed by authorities there.

Quebec goes further: a privacy impact assessment and a written agreement come before information leaves the province. The OPC also has draft guidance on assessing third-party service providers, open for comment until December 4, 2026.

## Email sign-ups and CASL

Canada's Anti-Spam Legislation applies to commercial electronic messages. For newsletter and marketing sign-ups:

- **Express consent must be opt-in.** No pre-checked boxes; silence isn't consent.
- **Ask separately** from your terms and conditions, identify who is asking, give contact details, and say consent can be withdrawn.
- **Keep proof** of consent.
- Implied consent from an existing business relationship lasts **2 years after a purchase** or **6 months after an inquiry**.
- Process **unsubscribe requests within 10 business days**, at no cost.

Administrative penalties reach $10M per violation for businesses.

## What Bill C-36 would change

After Bill C-27 died on the Order Paper in January 2025, the federal government tabled **Bill C-36, the Protecting Privacy and Consumer Data Act**, on June 15, 2026. As of late September 2026 it has only completed first reading. If passed in its current form, it would:

- replace Part 1 of PIPEDA with a standalone privacy law;
- require a formal **privacy management program**;
- add consent exceptions for "business activities" and "legitimate interest" — but not where the purpose is to influence a person's behaviour or decisions;
- require a **privacy impact assessment before transferring information outside Canada**;
- treat **children's information (under 18) as sensitive**, with a "best interests of the child" duty;
- create rights to **deletion** and **data mobility**, plus transparency for automated decision systems;
- introduce administrative penalties of up to the greater of **$10M or 3%** of global revenue, fines up to **$25M or 5%**, and a private right of action;
- move enforcement to a new Digital Safety and Data Protection Commission of Canada.

> **Build for where the law is going**
>
> Several of these proposals mirror what Quebec already requires. Designing to Law 25's standard today — privacy by default, PIAs for cross-border transfers, clear notices for automated decisions — is the most future-proof option for a national product.

## A privacy-by-design checklist for your next app

Use this list in discovery and again before launch:

1. **Map the data.** For every personal field: what it is, why you need it, where it's stored and who can access it.
2. **Collect less.** Remove fields that don't serve an identified purpose.
3. **Unbundle consent.** Separate required processing from optional uses such as marketing or analytics.
4. **Default to private.** Most-private settings by default; location and profiling off until the user opts in.
5. **Protect it.** Encryption in transit and at rest, least-privilege access, MFA for admin tools.
6. **Set retention rules** and build deletion into the product — not into a spreadsheet of reminders.
7. **Support rights requests.** Access, correction and (for Quebec) portability in a structured format.
8. **Vet vendors.** Contracts with every processor, and a cross-border notice in your privacy policy.
9. **Be breach-ready.** Detection, an incident register kept for at least 24 months, and a tested response plan.
10. **Explain automated decisions** wherever software, not a person, makes the call.
11. **Publish a clear privacy policy** that names your privacy officer.
12. **Check CASL** on every form that leads to marketing emails.

### Sources

- Office of the Privacy Commissioner of Canada — [PIPEDA in brief](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/) and [Guidelines for obtaining meaningful consent](https://www.priv.gc.ca/en/privacy-topics/collecting-personal-information/consent/gl_omc_201805/)
- [PIPEDA, sections 10.1–10.3 and 28](https://laws-lois.justice.gc.ca/eng/acts/P-8.6/page-3.html) (breach reporting, records and offences)
- OPC — [Guidelines for processing personal data across borders](https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/)
- [Quebec's Act respecting the protection of personal information in the private sector](https://www.legisquebec.gouv.qc.ca/en/showdoc/cs/P-39.1) and the [CAI's summary of Law 25](https://www.cai.gouv.qc.ca/protection-renseignements-personnels/sujets-et-domaines-dinteret/principaux-changements-loi-25)
- [Information and Privacy Commissioner of Ontario — PHIPA](https://www.ipc.on.ca/en/health-organizations/responding-to-a-privacy-breach/potential-consequences-of-a-breach-under-phipa)
- CRTC — [CASL FAQ](https://crtc.gc.ca/eng/com500/faq500.htm)
- Parliament of Canada — [Bill C-36 on LEGISinfo](https://www.parl.ca/legisinfo/en/bill/45-1/c-36) and [Government of Canada announcement](https://www.canada.ca/en/innovation-science-economic-development/news/2026/06/government-of-canada-tables-new-legislation-to-protect-childrens-data-strengthen-privacy-and-build-trust-in-the-digital-economy.html)

## Frequently asked questions

### Does PIPEDA apply to my Ontario business?

Most likely. Ontario has no general private-sector privacy law, so PIPEDA applies to Ontario organizations that collect, use or disclose personal information in the course of commercial activity. Health information custodians in Ontario are also covered by PHIPA.

### Does Canadian law require personal data to stay in Canada?

PIPEDA has no general data-residency requirement. You can use service providers abroad, but you remain accountable: protect the data by contract and tell individuals their information may be processed outside Canada. Quebec's Law 25 adds a privacy impact assessment before information leaves Quebec.

### Is Bill C-36 law yet?

No. Bill C-36, the proposed Protecting Privacy and Consumer Data Act, was tabled on June 15, 2026 and, as of late September 2026, had only completed first reading. Its details can still change before it passes.

### What counts as valid consent for marketing emails in Canada?

Under CASL, express consent must be opt-in: no pre-checked boxes, requested separately from terms and conditions, identifying who is asking, and stating that consent can be withdrawn. Unsubscribe requests must be processed within 10 business days.

## Put this guide into practice

- [Application Security](https://npcoding.ca/services/application-security/): Security built into every sprint: threat modeling, secure code, testing and privacy-by-design.
- [Web & Mobile App Development](https://npcoding.ca/services/application-development/): Web apps, mobile apps and customer portals built around the way your business actually works.

Start a project: https://npcoding.ca/contact/?topic=build&service=security&from=%2Fblog%2Fpipeda-privacy-compliance-app-development-canada%2F&type=article&id=pipeda-privacy-compliance-app-development-canada&cta=article#enquiry

---

NPCoding · AI-powered software & app development · Toronto, Canada · support@npcoding.com · https://npcoding.ca/contact/
