xmodoxmodo

Frameworks · Americas

PIPEDA

The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It is built on ten fair information principles, from accountability and consent to safeguards and individual access. Organisations must report a breach of security safeguards that creates a real risk of significant harm to the Office of the Privacy Commissioner. They must also notify affected individuals as soon as feasible.

Who it applies to

It applies to private-sector organisations that collect, use or disclose personal information in the course of commercial activity in Canada. This includes foreign companies handling Canadian residents' data. It does not apply where a substantially similar provincial law applies.

Main requirements

Principles

The ten principles are accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access and challenging compliance.

Safeguards

Security measures are proportionate to the sensitivity of the information.

Breach of safeguards

Organisations assess whether a breach creates a real risk of significant harm. They report to the Commissioner, notify individuals as soon as feasible, and keep a record of every breach.

Access & complaints

Individuals can access their information, and there is a process for challenging compliance.

How xmodo supports it

  • 1

    The ten principles are set up as controls with owners and evidence, alongside your security frameworks.

  • 2

    The breach workflow records the real-risk assessment, the report to the Commissioner, the notifications and the breach record that PIPEDA requires you to keep.

  • 3

    Requirements map to GDPR, CCPA/CPRA and the UAE PDPL, so one privacy programme serves each law.

Related frameworks

PIPEDA shares requirements with the frameworks below. Controls you already run for any of them count towards PIPEDA as well.

Frequently asked questions

Does PIPEDA set a fixed breach deadline?

No. Reports and notifications are due as soon as feasible after you determine that a breach of safeguards creates a real risk of significant harm. The timestamps on the incident record show that you acted promptly.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo