If your company has customers in Canada and you collect, use or disclose personal information in the course of commercial activities, you need to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). Configure PIPEDA.
Understanding PIPEDA
What is the PIPEDA?
The PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada’s federal data privacy law governing how private sector organizations collect, use and disclose personal information in the course of commercial activities. It came into force in 2000 and was amended by the Digital Privacy Act in 2015, which added mandatory data breach reporting.
PIPEDA is built around 10 fair information principles – chief among them the requirement to inform individuals about your data collection and to obtain their meaningful, prior consent. It is enforced by the Office of the Privacy Commissioner of Canada (OPC), and Canada holds an adequacy decision from the European Commission for data covered by PIPEDA.
What counts as personal information?
PIPEDA defines personal information broadly as any information about an identifiable individual, whether factual or subjective, recorded or not. This includes anything from names, addresses and purchase history to browsing and search history, as well as online identifiers such as IP (Internet Protocol) addresses, device identifiers and cookie data.
More sensitive categories – such as health and medical records, financial information, ethnic origin, religious beliefs and sexual orientation – are also covered, and generally require a higher standard of consent.
Who is required to comply?
Any private sector organization – anywhere in the world – that collects, uses or discloses the personal information of Canadian residents in the course of commercial activities is required to comply with PIPEDA. It does not matter where your business is based: if your website processes data from Canadian residents for commercial purposes, PIPEDA applies to you.
Federally regulated organizations operating in Canada are also subject to PIPEDA, including banks, airlines and airports, telecommunications companies, broadcasters and inter-provincial transportation companies, as are organizations operating in the Northwest Territories, Yukon and Nunavut.
Alberta, British Columbia and Quebec have their own private sector privacy laws that are considered substantially similar to PIPEDA. If you comply with those, you are generally exempt from PIPEDA for activity within the relevant province – but PIPEDA still applies once data crosses provincial or national borders. Note that Quebec’s Law 25 is stricter than PIPEDA and is explicitly opt-in, meaning cookies and other trackers may not be activated without prior explicit consent.
How do you make your website PIPEDA-compliant?
Your website must inform users what personal information you collect, and get their meaningful consent before you collect it. Consent is only valid under PIPEDA if it's reasonable to expect the person understands the nature, purpose, and consequences of the collection, use, or disclosure.
- Implied consent works when the information isn't sensitive and the collection falls within what a person would reasonably expect.
- Express consent (an active step, like clicking a button or checking a box) is required when the information is sensitive, the collection falls outside reasonable expectations, or there's a meaningful risk of significant harm.
Regardless of which applies, users must be informed in an easily accessible way, must be able to withdraw their consent at any time as easily as they gave it, and consent must be obtained again when you significantly change your data collection practices.
A Consent Management Platform (CMP) — like the one built into this product — handles this for you by managing consent and logging proof of consent for each site visitor.
Want to know more about PIPEDA? - Check out our blog post: PIPEDA: Canada’s data privacy law explained
Configure your CMP for PIPEDA
This guide focuses solely on the tools needed to make your website's use of cookies and online tracking compliant with PIPEDA. It doesn't cover other aspects of PIPEDA compliance.
These steps aren't intended as legal advice — if you're in doubt, seek advice from a trusted legal source or your data protection authority.
Setting up your CMP for PIPEDA compliance is straightforward — it's ready to use out of the box. Follow these steps to configure it.
First time set up
If you are setting up Cookiebot for the first time, you can select the PIPEDA preset. This will automatically configure the banner to comply with PIPEDA. You can still make some changes to suit your needs though.
Adding PIPEDA as an additional legislation
If you already have a CMP set up for another region, add PIPEDA as a separate domain group so the two configurations don't conflict.
Follow the following steps to create the additional domain group.
-
Add a new domain group.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
-
If you already have multiple domain groups: click "Manage" at the top of the domain group section in the left-hand menu.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
-
Click the "+ Create group" button
- Name the new group "PIPEDA" and click "Create group." You'll see it added to your list of domain groups.
-
Click the "Configure CMP" icon next to your new PIPEDA group to open its settings.
-
Click "Legislation presets" on the right side of the screen and select the PIPEDA preset.
-
Click "Save changes." Your PIPEDA domain group is now active and ready to use.
Comments
0 comments
Please sign in to leave a comment.