PIPEDA Compliance: Cookies and Consent in 2026

PIPEDA compliance for websites: does Canada's privacy law apply to you, the OPC rules for cookies and consent, Quebec Law 25 fines, and a plain checklist.

PIPEDA compliance for websites

PIPEDA is Canada’s federal privacy law, and complying with it means having a lawful reason to collect personal data, telling people what you collect and why, getting meaningful consent, keeping the data secure, and giving people a way to see or delete it. It reaches almost any business that handles personal information from people in Canada during commercial activity, and that includes websites run from outside the country. For most sites the practical work is small: a clear privacy notice, a cookie banner that holds tracking scripts until the visitor agrees, and a process for answering data requests.

Most PIPEDA guides are written for corporate privacy teams with lawyers down the hall. This one is written for the person who runs the website. It covers whether the law reaches you, what Canada’s privacy regulator expects around cookies and online tracking, how PIPEDA compares to the GDPR, why Quebec’s Law 25 carries far bigger fines, and a checklist you can work through on your own.

What is PIPEDA, and what does compliance mean?

PIPEDA is the Personal Information Protection and Electronic Documents Act, Canada’s federal law for how private businesses handle personal information, and compliance means following its rules every time your site collects, uses, or shares that data. Parliament passed it in 2000, and it applied to all commercial activity across the country by 2004.

What is PIPEDA

Personal information under PIPEDA is any data about an identifiable person. That covers the obvious things like a name, an email address, or a phone number, and the less obvious ones like an IP address, a cookie identifier, device details, and location. If a piece of data can be tied back to a real human, the law treats it as personal information, and your website is responsible for it.

The law is built on ten fair information principles, set out in a schedule that reads like a plain checklist. You have to be accountable for the data you hold and put someone in charge of it. You have to identify why you’re collecting information before or at the moment you collect it, and get consent for those purposes. You can only gather what you actually need, use it for the reason you gave, and keep it no longer than necessary. The data has to be accurate and protected by real security, and your practices have to be open, so a person can find out what you do and get access to their own record. If they think you got something wrong, they need a way to challenge it.

Consent is the thread running through all of it. PIPEDA asks for meaningful consent, which means the person actually understood what they agreed to. How you get that consent depends on how sensitive the data is, and that single idea shapes almost everything a website has to do.

Does PIPEDA apply to your website?

If your website collects personal information from people in Canada as part of doing business, PIPEDA almost certainly applies, even when your company, your servers, and your team sit in another country. The law attaches to the data of people in Canada, not to your address.

Does PIPEDA apply to your website

The trigger is commercial activity, so if you sell a product, run ads, capture leads, or do anything that trades on the data, you’re in commercial territory and the law is in play. A software company in Berlin with paying Canadian customers is bound by PIPEDA for those customers’ data, the same as a shop in Toronto. Charities and purely personal projects sit outside it, but a business that treats a Canadian visitor as a potential customer is inside.

Federally regulated businesses are a special case. Banks, airlines, telecom and internet providers, and interprovincial transport companies fall under PIPEDA for all their activity, including their employees’ data, no matter which province they operate in.

Three provinces complicate the map, because Quebec, British Columbia, and Alberta each have their own private-sector privacy laws that Canada considers substantially similar to PIPEDA. A business operating only inside one of those provinces follows the provincial law for local activity, while PIPEDA still governs data that crosses a provincial or national border. For a website that reaches the whole country, the safe assumption is that PIPEDA and, for Quebec visitors, Law 25 both apply. If you already handle the CCPA for California users or the LGPD for Brazil, this is the Canadian layer of the same job.

For most websites the answer is yes, because the moment your site drops a cookie that tracks or profiles a visitor, that cookie is handling personal information, and PIPEDA’s consent rules apply to it.

PIPEDA cookie consent banner

The Office of the Privacy Commissioner, Canada’s regulator, has said plainly that data collected through cookies for online tracking and targeting is personal information. That pulls analytics and advertising cookies into the same consent framework as anything else you collect. Strictly necessary cookies, the ones that make a login or a cart work, don’t need consent, but the tracking ones do.

Here PIPEDA is more flexible than Europe’s rules, and the flexibility trips people up. Because the form of consent depends on sensitivity, the regulator accepts opt-out consent for ordinary online advertising in some cases, rather than demanding a hard opt-in for everything. But that flexibility comes with strict conditions. You have to tell people what you collect in a way they can’t miss, not buried in a privacy policy nobody opens. You have to give that notice at or before the moment of collection, and name the other companies the data goes to. The opt-out has to be easy to find, take effect right away, and stay in effect. And you can only rely on it for non-sensitive information that you delete or de-identify once you’re done with it. Anything sensitive, like health or financial details, needs express opt-in, and the regulator says to avoid tracking children altogether.

In practice that points to the same tool a GDPR site already uses: a banner that discloses your tracking clearly, holds non-essential scripts until the visitor makes a choice, offers a real reject option, and records what they picked. A cookie consent widget that gates declared scripts does exactly this, and it keeps a consent log you can produce if the regulator ever asks. If you build the banner to the opt-in standard of a good cookie consent setup and wire it into Google Consent Mode, you clear the PIPEDA bar and the stricter Quebec one at the same time.

PIPEDA vs GDPR: what is actually different?

PIPEDA and the GDPR share the same backbone, a lawful basis for handling data plus real rights for the individual, but PIPEDA leans on flexible consent and carries much weaker fines. If you have already done the GDPR work, you are most of the way to PIPEDA.

PIPEDA vs GDPR comparison

The table below lays out where the two laws diverge for a typical website.

AreaPIPEDA (Canada)GDPR (EU)
Consent modelMeaningful consent, express or implied depending on sensitivityFreely given and specific, mostly a clear opt-in
Who it coversPrivate businesses handling data in commercial activityAny organisation processing EU residents’ data
CookiesTracking cookies need consent, opt-out can suffice for non-sensitive useNon-essential cookies need prior opt-in
Maximum penaltyCAD $100,000 per offence, and only for specific breachesUp to 20 million euro or 4 percent of global turnover
Regulator powerThe OPC investigates and recommends, courts impose finesData protection authorities fine directly
Breach reportingReport to the OPC and affected people on real risk of significant harmReport to the authority within 72 hours

The practical takeaway is that a GDPR-grade privacy setup covers PIPEDA comfortably. The reverse is not true, because PIPEDA’s opt-out allowance and its lighter penalties would leave gaps in Europe. The biggest day-to-day difference is enforcement. A GDPR regulator can fine you straight away, while Canada’s Commissioner has to work through the courts, which changes how the risk feels for a small business.

Quebec’s Law 25, CASL, and the reform that stalled

Quebec runs its own privacy law, Law 25, and it is stricter than PIPEDA with penalties big enough to change how you build. Any site with Quebec visitors has to account for it on top of the federal rules.

Quebec Law 25 penalties

Law 25 modernised Quebec’s private-sector privacy regime in phases between 2022 and 2024, and the final set of provisions took effect on September 22, 2024. It asks for more than PIPEDA does. Consent has to be sought for each purpose and, for sensitive data, given expressly. You have to name a person responsible for privacy and publish their role. Higher-risk projects need a privacy impact assessment before they start, and people gained a right to move their data to another provider. The penalties are where it bites: administrative monetary penalties reach CAD $10 million or 2 percent of worldwide turnover, and penal fines climb to CAD $25 million or 4 percent of worldwide turnover, whichever is greater. Those numbers put Quebec in GDPR territory, far above PIPEDA’s ceiling.

Canada’s Anti-Spam Legislation, known as CASL, is a separate law that often gets folded into the same compliance job. It governs commercial electronic messages, so it covers your marketing email and SMS rather than your cookies. To send them you generally need consent, a working unsubscribe in every message, and clear sender identification. Fines run up to CAD $10 million per violation for a business, so a careless newsletter setup carries its own risk.

Reform has been promised for years and keeps slipping. Bill C-27 would have replaced part of PIPEDA with a new Consumer Privacy Protection Act and added Canada’s first law on artificial intelligence. It died when Parliament was prorogued in January 2025, and a federal election followed that spring. So the framework you have to comply with in 2026 is still PIPEDA plus the provincial laws, and any guide that tells you to prepare for the CPPA is describing a bill that never passed.

What are the penalties, and how is PIPEDA enforced?

PIPEDA’s direct fines are small, but enforcement runs through the Office of the Privacy Commissioner and the Federal Court, and the reputational cost of a public finding is usually the bigger risk. The law works more like an ombudsman than a fining machine.

PIPEDA penalties and enforcement

Someone who thinks you mishandled their data complains to the Commissioner, who can investigate, audit your practices, and publish findings. The Commissioner can recommend changes and name organisations that fall short, but it cannot impose administrative fines by itself. To force the issue, a matter goes to the Federal Court, where a judge can order you to change course and where the individual can seek damages. A handful of specific offences carry statutory fines up to CAD $100,000, and they target the failures the law cares most about: knowingly failing to report or record a breach, obstructing the Commissioner, or punishing an employee who blew the whistle.

Breach reporting is the obligation most sites overlook. Since November 1, 2018, any organisation under PIPEDA has to report a breach of security safeguards to the Commissioner, notify the people affected, and keep a record of every breach, whenever the breach creates a real risk of significant harm to someone. You judge that risk by how sensitive the data is and how likely it is to be misused, and you have to act as soon as feasible after you find the problem. Compared with Quebec’s Law 25, the federal fines look gentle, which is exactly why the Commissioner leans on public findings and why the honest, well-documented site comes out ahead.

Your PIPEDA compliance checklist

Making a website PIPEDA-ready comes down to a handful of concrete jobs, and none of them need a law degree. Work through them in order and you cover the ten principles without ever reading the statute.

PIPEDA compliance checklist

Start with a plain privacy policy. It should name what you collect, why you collect it, who you share it with, how long you keep it, and how someone reaches you to ask about their data. Write it so a normal visitor understands it, because a policy nobody can read fails the openness principle even when the words are technically correct.

Next, map your data by walking your site and listing every place personal information enters: contact and signup forms, analytics, advertising pixels, a chat box, an embedded feed, a booking tool. You can’t protect, disclose, or delete what you never wrote down, so this inventory is the spine of everything else.

Then fix consent at the front door. Put up a cookie banner that holds non-essential scripts until the visitor agrees, offers a genuine reject, and logs the choice with a date. Keep your forms lean by asking only for the fields you truly use, which shrinks the pile of data you have to guard. Amabrik’s forms pass each submission straight to your CRM or inbox without storing it, so there is nothing extra sitting on a server waiting to leak.

Build a way to answer people. A monitored privacy email and a simple internal step to find, export, or delete a person’s record covers the access and correction rights, and doing it within a reasonable time keeps you clear of a complaint. Pair that with a short breach plan: who assesses real risk of significant harm, who notifies the Commissioner and the affected people, and where you log it. Finally, check your vendors, because your analytics, email, and hosting providers process data on your behalf and their settings and contracts are part of your compliance, not an afterthought. A dedicated cookie and consent tool handles the banner and the log for you, which is why many teams reach for one instead of stitching together scripts, the same reason people move off heavier suites like OneTrust.

PIPEDA rewards the site that is honest about what it collects and careful about how it asks, and it goes hardest on the one that hides the ball. The work is mostly clarity: say what you gather, gather less, ask before you track, and be ready when someone wants to see or delete their record.

For a typical website the load is lighter than it looks. Assume the law applies if Canadian visitors use your site, get the cookie banner and the consent log right, keep your forms minimal, and have a plan for requests and breaches. Remember that Quebec’s Law 25 raises the stakes with real fines, so treat Quebec users as the strict case and you cover the rest of the country by default. A cookie consent widget that gates tracking scripts and records every choice does the heaviest part of that work, and it leaves you with a clean record to show if anyone ever asks.

FAQ

Questions, answered

Still stuck on something? Ask us and we answer fast.

PIPEDA is Canada's federal privacy law for the private sector. It sets the rules a business follows when it collects, uses, or shares someone's personal information during commercial activity. In plain terms, you need a real reason to collect data, you have to tell people what you're doing and get meaningful consent, you have to keep the data secure, and you have to let people see or delete what you hold on them. It has been the law since 2000 and applied nationwide by 2004.

Yes, in most cases, because PIPEDA follows the personal information of people in Canada, not your company's address. If your website collects data from Canadian visitors as part of doing business, through forms, analytics, or tracking cookies, you're generally in scope even if your company, servers, and staff sit elsewhere. Canadian regulators and courts have applied the law to foreign organizations that have a real connection to Canada.

For most sites the answer is yes, because the Office of the Privacy Commissioner treats data collected by tracking and advertising cookies as personal information, so it falls under PIPEDA's consent rules. You have to tell visitors clearly, not bury it in a privacy policy, and give them an easy way to opt out that takes effect right away. A banner that holds non-essential scripts until the visitor agrees, offers a genuine reject, and records the choice meets that bar, and a setup built for the GDPR already covers it.

PIPEDA is the federal law and applies across Canada, while Law 25 is Quebec's own private-sector privacy law and it is stricter. Law 25 requires consent by default, a named privacy officer, and privacy impact assessments for higher-risk projects, and its final provisions took effect on September 22, 2024. The penalties are the biggest gap: PIPEDA offences top out at CAD $100,000, while Law 25 allows fines up to CAD $25 million or 4 percent of worldwide turnover, whichever is greater.

PIPEDA's direct fines are modest, and the Privacy Commissioner investigates and publishes findings but cannot levy fines on its own, so matters go to the Federal Court, where individuals can also seek damages. Specific offences, like knowingly failing to report or record a breach, or obstructing the Commissioner, carry fines up to CAD $100,000. The larger cost is usually reputational, and Quebec's Law 25 adds much heavier penalties for sites with Quebec users.

Not for now, because Bill C-27 would have replaced part of PIPEDA with the Consumer Privacy Protection Act and added rules for artificial intelligence, but it died when Parliament was prorogued in January 2025, followed by a federal election. As of 2026, PIPEDA is still Canada's federal privacy law, so you should build for PIPEDA and Quebec's Law 25 as they stand today, not for a bill that has not passed.

Nicolas Lecocq
Nicolas Lecocq Founder, Amabrik

16 years building web products. Created OceanWP (500,000+ sites) and now Amabrik: every website widget in one light snippet, no pageview caps, nothing about your visitors stored on our side.

Newsletter

Get the next guide in your inbox

One short, useful email when we publish. No spam, unsubscribe anytime.