Law guide
PIPEDA privacy policy: Canadian openness requirements
PIPEDA does not prescribe a single privacy-policy template, but its openness principle requires organizations to make specific, understandable information about their personal-information policies and practices readily available. In practice a Canadian privacy policy should name the person accountable and how to reach them, describe the personal information held and how it is used and disclosed, explain how to request access, and describe how to complain.
Who this law applies to
PIPEDA applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity. It also covers federally regulated works and businesses, such as banks, airlines, and telecommunications companies, including their employee information. Quebec, British Columbia, and Alberta have private-sector privacy laws that are substantially similar, and those provincial laws generally govern activity within the province, while PIPEDA continues to apply to personal information that crosses provincial or national borders in the course of commercial activity. There is no revenue threshold or small-business exemption. Organizations based outside Canada can also be subject to PIPEDA when their activities have a real and substantial connection to Canada, for example when they actively serve Canadian customers. Complaints go to the Office of the Privacy Commissioner of Canada.
What your privacy policy must include
PIPEDA's requirements sit in the ten fair information principles in Schedule 1. The openness principle, clause 4.8, asks organizations to make available the name or title and address of the person accountable for compliance and to whom complaints or inquiries can be forwarded; the means of gaining access to personal information; a description of the type of personal information held, including a general account of its use; any brochures or other information explaining policies, standards, or codes; and what personal information is made available to related organizations such as subsidiaries. The other principles shape the content: accountability requires a designated person; identifying purposes requires stating why information is collected at or before collection; consent must be meaningful, which the Commissioner's guidance links to clear explanations of what is collected, with whom it is shared, for what purposes, and the risks of harm; limiting use, disclosure, and retention requires retention practices; individual access and challenging compliance require working procedures. Regulator guidance also expects organizations to tell people when information may be processed or stored in another country and may be accessible to authorities there.
How Legal Policy Generator handles it
Selecting Canada PIPEDA adds a regional clause that summarizes the fair information principles the operator follows and explains that individuals may ask about the existence, use, and disclosure of their information, request access or correction, or challenge compliance, with a pointer to the Office of the Privacy Commissioner of Canada. The general collection, uses, sharing, transfers, and retention sections carry the factual detail. A separate Quebec clause covers the publication duty that Law 25 added to Quebec's private-sector act: it publishes the title and email of the person in charge of protecting personal information, states whether technology that can identify, locate, or profile a person is used and how its functions are activated, describes the assessment and written agreement required before communication outside Quebec when information is processed abroad or the operator is based outside Canada, and lists access, rectification, portability, and consent withdrawal with a pointer to the Commission d'accès à l'information. Quebec consent, governance, and incident duties that sit outside a published policy still need separate review. Because clauses are versioned, a generated policy keeps the clause versions recorded with it, and regeneration creates a new immutable version instead of rewriting the published one. The list below is read from the clause library each time this page is rendered.
Privacy Policy clauses for this law
Clauses in the current library that carry this jurisdiction in their metadata: 2
Identifiers, versions, required answers, review dates, and sources below are read from the clause files when this page is generated.
pipeda-rights v1.1.0 · Privacy Policy · Canada PIPEDA privacy rights
Required answers: rights_methods. Reviewed . Official source: laws-lois.justice.gc.ca.
Where Canada's PIPEDA applies, the operator follows accountability, identified purposes, meaningful consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and complaint-handling principles. … Complaints may also be directed to the Office of the Privacy Commissioner of Canada where applicable.
Excerpt from clause pipeda-rights v1.1.0quebec-privacy v1.0.0 · Privacy Policy · Quebec privacy disclosures
Required answers: quebec_officer_title, quebec_officer_email, quebec_profiling, rights_methods. Reviewed . Official source: www.legisquebec.gouv.qc.ca, www.cai.gouv.qc.ca.
… A person may request access to personal information about them; rectification of information that is inaccurate, incomplete, or equivocal, or whose collection, communication, or keeping is not authorized by law; communication of computerized personal information they provided, to them or …
Excerpt from clause quebec-privacy v1.0.0
Related Terms of Use clauses for the same region
These clauses belong to the separate Terms of Use generator. They address consumer or platform rules for the region, not privacy notices, and activate only from Terms questionnaire answers.
terms-ca-consumer v1.1.0 · Terms of Service · Canadian consumer rights
Reviewed . Official source: ised-isde.canada.ca.
Questionnaire answers that switch it on
The Canada clause activates only when the jurisdiction answer includes Canada PIPEDA. It requires the privacy request methods you actually support, such as a privacy email, account settings, or a web form, and names only those methods. Answers about international processing and transfer locations feed the transfers section, which is where cross-border storage is described. The Quebec clause activates separately when the jurisdiction answer includes the Quebec private-sector act; it then requires the title and email of the person in charge of protecting personal information, an answer about identification, location, or profiling technology, and, when that technology is used, how a person activates it. In the separate Terms generator, selecting Canada for consumer terms adds a clause preserving mandatory Canadian consumer rights.
Common mistakes
Omitting a named accountable person or role leaves out the first item the openness principle expects. Describing purposes in open-ended terms such as improving services makes meaningful consent hard to claim. Bundling consent for unrelated purposes into one acceptance is a frequent problem in regulator findings. Not mentioning that a cloud or support provider stores information outside Canada misses a transparency point that Canadian regulators emphasize. Assuming that a small business is exempt is wrong under PIPEDA. Treating a PIPEDA-based policy as complete for Quebec residents ignores Law 25, which has its own publication, governance, and consent requirements. Finally, PIPEDA requires organizations to report breaches of security safeguards that create a real risk of significant harm to the Commissioner, notify affected individuals, and keep records of every breach, so the security section should not suggest otherwise.
Official sources checked for this guide
Platform rules and legislation can change. Verify the current text before publishing or making a high-risk decision.
Common questions
Is there a small business exemption under PIPEDA?
No. PIPEDA applies to organizations that handle personal information in the course of commercial activity regardless of size.
Does the generator cover Quebec Law 25?
Partly. Selecting the Quebec module adds the published policy content: the person in charge of protecting personal information, identification, location, or profiling technology, communication outside Quebec, and rights. Other Law 25 duties, such as consent and governance, still need separate review.
Should a Canadian privacy policy mention storage outside Canada?
Regulator guidance expects organizations to tell people when their information may be processed in another country and may be accessible to authorities there.
Where can individuals complain about a PIPEDA issue?
To the organization first, and to the Office of the Privacy Commissioner of Canada, which the generated clause names as a complaint route where applicable.
Is the generated Canadian wording legal advice?
No. It reflects supplied facts and does not guarantee compliance with federal or provincial law.