{
 "jurisdiction_id": "CA-ON",
 "jurisdiction": "Canada – Ontario",
 "url": "https://dataprotection.gi/jurisdictions/canada-ontario/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 61,
  "sub_modules": 57,
  "source_register": 29
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Framework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.",
   "claims": [
    {
     "statement": "The Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/memorandums-of-understanding-with-provinces/mou_on_2025/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2025/pipeda-2025-002/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-new-pipeda-data-breach-notification-requirements-twelve-years-in-the-making",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.",
   "claims": [
    {
     "statement": "Consent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/matchup-canadas-pipeda-and-the-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 6.1 of PIPEDA provides that consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_63_s4/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Since the 2015 Digital Privacy Act amendments, organizations may disclose personal information without consent to investigate a breach of agreement/law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_63_s4/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/an-update-of-c-27-since-its-reintroduction-in-parliament",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.",
   "claims": [
    {
     "statement": "Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "After investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2025/pipeda-2025-002/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Bill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2026/parl_260126/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).",
   "claims": [
    {
     "statement": "PIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/an-update-of-c-27-since-its-reintroduction-in-parliament",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-new-pipeda-data-breach-notification-requirements-twelve-years-in-the-making",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Principle 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda-complaints-and-enforcement-process/enforcement-of-pipeda/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Significant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2025/pipeda-2025-002/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-and-transparency-at-the-opc/proactive-disclosure/opc-parl-bp/ab_20240924/is_ab_20240924/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Adequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.",
   "claims": [
    {
     "statement": "PIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52024DC0007",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Canada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-and-transparency-at-the-opc/proactive-disclosure/opc-parl-bp/ab_20240924/is_ab_20240924/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Canada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/matchup-canadas-pipeda-and-the-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2026/parl_260126/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2026/parl_260126/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Health sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.",
   "claims": [
    {
     "statement": "Federally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/joint-resolutions-with-provinces-and-territories/res_231005_02/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "At the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/canadas-anti-spam-legislation/casl-compliance-help-for-businesses/casl_guide/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/joint-resolutions-with-provinces-and-territories/res_231005_02/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Canada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/joint-resolutions-with-provinces-and-territories/res_231005_02/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Municipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.",
   "claims": [
    {
     "statement": "The OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-case-of-the-unsolicited-email",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Implied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-case-of-the-unsolicited-email",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "With very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/canadas-anti-spam-legislation/casl-compliance-help-for-businesses/casl_guide/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.",
   "claims": [
    {
     "statement": "The CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/an-update-of-c-27-since-its-reintroduction-in-parliament",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/an-update-of-c-27-since-its-reintroduction-in-parliament",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/canada-bill-c-27-dies-after-parliament-prorogued",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/what-2026-may-bring-for-canadas-privacy-reform-efforts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-and-transparency-at-the-opc/proactive-disclosure/opc-parl-bp/ab_20240924/is_ab_20240924/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ontario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.",
   "claims": [
    {
     "statement": "Commentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/what-2026-may-bring-for-canadas-privacy-reform-efforts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/canada-ontario/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Ontario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.",
   "claims": [
    {
     "statement": "The OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_63_s4/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202526/ar_202526/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202526/ar_202526/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/what-2026-may-bring-for-canadas-privacy-reform-efforts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/ontario",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/risky-business-to-business-communications-casl-lessons-from-the-compufinder-case",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202526/ar_202526/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-news/speeches-and-statements/2026/s-d_260506/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Commissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OPC",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202526/ar_202526/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}