🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA-NB · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 23 sources retrieved model claude-sonnet-5 ·

Canada – New Brunswick

CA-NB schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Regulator identity, governing instruments and material/territorial scope are clearly documented across multiple official OPC sources.

Primary frameworkPIPEDA (federal, private sector) + Right to Information and Protection of Privacy Act, SNB 2009 c R-10.6 (public sector) + Personal Health Information Privacy and Access Act, SNB 2009 c P-7.05 (health sector)
Traffic-light rationale — GreenRegulator identity, governing instruments and material/territorial scope are clearly documented across multiple official OPC sources.

Sub-modules (5)

Regulator And AuthorityGreen

OPC enforces PIPEDA nationally including in NB; the NB Ombud separately enforces RTIPPA (public sector) and PHIPAA (health sector).

Claims: 00000001, 00000002

Act And InstrumentsGreen

Three instruments together constitute NB's regime: PIPEDA, RTIPPA, and PHIPAA.

Claims: 00000003

Material ScopeGreen

PIPEDA's commercial-activity scope fills NB's private-sector gap since no NB-specific substantially-similar private sector statute exists.

Claims: 00000004, 00000005

Territorial ScopeGreen

PIPEDA applies to any business handling personal information crossing provincial/national borders regardless of home province.

Claims: 00000006

Regulator Registration And FilingRed

No general controller registration or filing regime was identified for NB under PIPEDA, RTIPPA, or PHIPAA in this research pass.

Category narrative124 words

New Brunswick's data-protection position is a layered federal/provincial construct rather than a single provincial omnibus statute. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs private-sector commercial-activity data across the province because New Brunswick has not enacted a general private-sector statute deemed 'substantially similar' to PIPEDA (unlike Alberta, BC and Quebec). Two New Brunswick statutes overlay this: the Right to Information and Protection of Privacy Act (RTIPPA) for public bodies, and the Personal Health Information Privacy and Access Act (PHIPAA) for health information custodians (the latter deemed substantially similar to PIPEDA for that sector). Both provincial statutes are overseen by the Office of the Ombud for New Brunswick; PIPEDA is overseen federally by the Office of the Privacy Commissioner of Canada (OPC).

#

Lawful bases, consent and sensitive-data coverage are well evidenced; anonymisation/pseudonymisation specifics are an evidence gap.

Primary frameworkPIPEDA Schedule 1 (10 Fair Information Principles)
Traffic-light rationale — AmberLawful bases, consent and sensitive-data coverage are well evidenced; anonymisation/pseudonymisation specifics are an evidence gap.

Sub-modules (4)

Lawful BasesGreen

The 10 Schedule 1 principles operate as PIPEDA's lawful-processing framework.

Claims: 00000007

Special CategoriesAmber

PIPEDA's personal information definition explicitly includes sensitive categories such as medical records and ethnic origin.

Claims: 00000009

Pseudonymisation And AnonymisationRed

No PIPEDA-specific anonymisation/pseudonymisation safe-harbour provisions were located; searched OPC guidance pages and summary-of-laws resources without a definitive NB-applicable standard.

Category narrative69 words

PIPEDA's Schedule 1 sets out ten fair information principles functioning as NB's private-sector lawful-processing framework, with a 2015 (Digital Privacy Act) amendment clarifying the standard for valid/meaningful consent. PIPEDA's definition of personal information expressly captures sensitive categories (medical records, ethnic origin, etc.), though PIPEDA does not use a discrete 'special category' regime analogous to GDPR Art 9. Pseudonymisation/anonymisation safe-harbour rules specific to PIPEDA were not located in this pass.

#

Only the access-right sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Primary frameworkPIPEDA Schedule 1, Principle 9 (Individual Access); RTIPPA (public sector access/correction, NB)
Traffic-light rationale — RedOnly the access-right sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Sub-modules (5)

Access RightAmber

PIPEDA permits refusal of access only in narrow, enumerated circumstances (e.g., solicitor-client privilege).

Claims: 00000010

Rectification And ErasureRed

No PIPEDA/RTIPPA-specific rectification or erasure provision text was retrieved in this pass; searched OPC guidance and provincial-law summary pages.

Restriction And ObjectionRed

No restriction/objection-specific provision was retrieved for PIPEDA, RTIPPA or PHIPAA in this pass.

Data PortabilityRed

No portability right currently exists under PIPEDA; a proposed portability mechanism under the Consumer Privacy Protection Act (part of Bill C-27) never came into force after the Bill died on prorogation.

Deadlines And Response WindowsRed

Statutory response-deadline specifics for PIPEDA/RTIPPA/PHIPAA access requests were not retrieved in this pass.

Category narrative43 words

PIPEDA's access-right framework (with narrow statutory exceptions under s.9(3)) is documented, but rectification/erasure, restriction/objection, portability and statutory response-deadline specifics under PIPEDA/RTIPPA/PHIPAA were not confirmed in this research pass; Canada's proposed portability and ADM-contest rights (under the now-dead Bill C-27 CPPA) never took effect.

#

Breach notification, accountability and security-safeguard duties are strongly evidenced; DPO/ROPA/joint-controller sub-modules are gaps because PIPEDA does not impose GDPR-style discrete obligations of this kind.

Primary frameworkPIPEDA (breach-of-security-safeguards regime, s.10.1; Schedule 1 Principles 4.1 (Accountability) and 4.7 (Safeguards)); PHIPAA (NB health-sector breach notification)
Traffic-light rationale — AmberBreach notification, accountability and security-safeguard duties are strongly evidenced; DPO/ROPA/joint-controller sub-modules are gaps because PIPEDA does not impose GDPR-style discrete obligations of this kind.

Sub-modules (7)

Accountability And DpiaAmber

PIPEDA's accountability principle keeps organizations responsible for information transferred to third parties for processing.

Claims: 00000011

Dpo RequirementsRed

No PIPEDA/RTIPPA/PHIPAA statutory DPO-appointment threshold was located in this pass.

Ropa RequirementsRed

No discrete records-of-processing (ROPA) obligation analogous to GDPR Art 30 was located under PIPEDA, RTIPPA or PHIPAA.

Joint Controller ArrangementsRed

No joint-controller-specific statutory framework was located under PIPEDA, RTIPPA or PHIPAA in this pass.

Security MeasuresGreen

PIPEDA's breach-of-security-safeguards definition ties directly to Schedule 1 Principle 4.7 security obligations.

Claims: 00000012

Breach NotificationGreen

PIPEDA's RROSH-based mandatory breach reporting/notification regime and its penalty structure are well documented; NB's PHIPAA imposes parallel health-sector breach-notification duties.

Claims: 00000013, 00000014, 00000015

Retention And DisposalGreen

PIPEDA requires two-year retention of breach records for OPC inspection.

Claims: 00000016

Category narrative105 words

Breach notification is the best-evidenced duty in this module: PIPEDA requires reporting to the OPC and notifying affected individuals where a breach poses a 'real risk of significant harm' (RROSH), with knowing non-compliance punishable by fines up to $100,000 (prosecuted federally, not administratively imposed by OPC). NB's PHIPAA sits within a small cluster of provincial health-privacy statutes (with Ontario, Nova Scotia, Newfoundland and Labrador) imposing similar mandatory breach-notification duties on health custodians. Accountability (including responsibility for third-party processors) and security-safeguard obligations (Schedule 1, Principle 4.7) are documented. DPO appointment thresholds, formal ROPA requirements, and joint-controller-arrangement rules were not located as distinct statutory features of PIPEDA/RTIPPA/PHIPAA.

#

Transfer mechanism, adequacy-received status and NB health-sector localisation rule are evidenced; SCC/BCR, TIA and adequacy-granted sub-modules are gaps because Canada's regime does not operate GDPR-equivalent instruments in these areas.

Primary frameworkPIPEDA (accountability-based transfer regime); EU Commission adequacy decision for Canada (organizations subject to PIPEDA); PHIPAA s.19 (NB, cross-border health-data consent)
Traffic-light rationale — AmberTransfer mechanism, adequacy-received status and NB health-sector localisation rule are evidenced; SCC/BCR, TIA and adequacy-granted sub-modules are gaps because Canada's regime does not operate GDPR-equivalent instruments in these areas.

Sub-modules (6)

Transfer MechanismsGreen

PIPEDA requires contractual/other means to ensure comparable protection when personal information is processed by third parties, domestically or cross-border.

Claims: 00000017

Adequacy ReceivedAmber

The EU renewed its adequacy decision covering PIPEDA-subject Canadian organizations in January 2024, tied partly to the (since-lapsed) Bill C-27 reform trajectory.

Claims: 00000018

Adequacy GrantedRed

No adequacy decisions granted by Canada/NB to other jurisdictions were located in this pass.

Sccs And BcrsRed

PIPEDA does not operate an SCC/BCR-equivalent certification regime; none was located.

Transfer Impact AssessmentRed

No PIPEDA/PHIPAA/RTIPPA transfer-impact-assessment obligation was located in this pass.

Data LocalisationAmber

PHIPAA imposes an express-consent requirement (s.19) for disclosure of personal health information outside New Brunswick.

Claims: 00000019

Category narrative96 words

PIPEDA relies on an accountability-based transfer mechanism (contractual/other means providing comparable protection) rather than a GDPR-style SCC/BCR/TIA regime. Canada (via PIPEDA-covered organizations) holds an EU adequacy decision, renewed in January 2024, with the European Commission expressly citing then-pending Bill C-27 reforms as a factor it would continue to monitor (Bill C-27 subsequently died on prorogation in January 2025, creating some uncertainty about future EU monitoring outcomes). NB's PHIPAA imposes an express-consent requirement for cross-border disclosure of personal health information. No SCC/BCR-equivalent instruments, formal transfer-impact-assessment obligation, or outbound adequacy grants from Canada/NB to other regimes were located.

#

Financial, health, employment, credit and insurance overlays are evidenced; telecoms/ePrivacy and education sub-modules are gaps in this pass.

Primary frameworkPIPEDA plus sectoral overlays: Bank Act (financial); PHIPAA (health); provincial consumer-credit-reporting statutes (credit)
Traffic-light rationale — AmberFinancial, health, employment, credit and insurance overlays are evidenced; telecoms/ePrivacy and education sub-modules are gaps in this pass.

Sub-modules (7)

Financial Sector OverlayAmber

The Bank Act regulates personal financial information handling by federally regulated financial institutions, in parallel with PIPEDA.

Claims: 00000020

Health Sector OverlayGreen

PHIPAA displaces PIPEDA for NB health information custodians as a substantially similar sectoral law.

Claims: 00000021

Telecoms And EprivacyRed

No telecoms/ePrivacy-specific statute (e.g., CASL) detail was retrieved as part of this research pass.

Employment DataAmber

PIPEDA covers employee/applicant personal information for federally regulated works, undertakings and businesses.

Claims: 00000022

Credit And ScoringAmber

Provincial consumer-credit-reporting laws impose confidentiality obligations on credit agencies alongside PIPEDA.

Claims: 00000023

EducationRed

No NB-specific education-sector statute was retrieved; cross-jurisdictional EdTech privacy guidance is captured under children_and_vulnerable_groups instead.

InsuranceAmber

Insurance companies are treated as PIPEDA-subject organizations for breach-reporting purposes.

Claims: 00000024

Category narrative84 words

Multiple sector overlays intersect with PIPEDA in NB: the federal Bank Act regulates federally-regulated financial institutions' handling of personal financial information; PHIPAA displaces PIPEDA for NB health custodians; PIPEDA covers FWUB employee/applicant data; provincial consumer-credit-reporting laws impose confidentiality duties on credit agencies; and insurance companies are treated as PIPEDA-subject organizations for RROSH breach-reporting purposes. Telecoms/ePrivacy-specific rules (e.g., Canada's Anti-Spam Legislation) and NB-specific education-sector privacy rules were not directly retrieved in this pass (education is partly addressed via the cross-jurisdictional EdTech resolution captured under children_and_vulnerable_groups).

#

Only one of six sub-modules (dark patterns) has direct evidentiary support in this pass.

Traffic-light rationale — RedOnly one of six sub-modules (dark patterns) has direct evidentiary support in this pass.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-consent-specific statute was retrieved in this pass beyond PIPEDA's general consent principles.

Dark PatternsAmber

OPC publishes non-binding guidance on deceptive design patterns affecting personal-information disclosure.

Claims: 00000025

Opt Out SignalsRed

No Global-Privacy-Control-equivalent recognition regime was retrieved for Canada/NB.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rules were retrieved.

Cross Context AdvertisingRed

No cross-context-advertising-specific ('sale'/'share') statute was retrieved for Canada/NB.

Direct MarketingRed

Canada's Anti-Spam Legislation (CASL) is the likely relevant instrument for direct-marketing consent/suppression but was not researched in this pass; absent_field_provenance applies.

Category narrative35 words

Evidence in this pass is limited to OPC guidance on deceptive design patterns ('dark patterns'). No NB/federal cookie-consent statute, opt-out-signal recognition regime (e.g., GPC), clean-room rules, cross-context-advertising regime, or direct-marketing-specific statute (e.g., CASL) was retrieved.

#

The historical/current non-force status of AIDA and ADM-contest proposals is well evidenced; profiling, genetic-data and surveillance-carveout sub-modules remain gaps.

Traffic-light rationale — AmberThe historical/current non-force status of AIDA and ADM-contest proposals is well evidenced; profiling, genetic-data and surveillance-carveout sub-modules remain gaps.

Sub-modules (6)

Profiling RestrictionsRed

No PIPEDA-specific profiling-restriction provision analogous to GDPR Art 22 was retrieved in this pass.

Automated Decision Making TransparencyAmber

A proposed statutory right to contest automated decisions under the CPPA never came into force after Bill C-27 died on prorogation.

Claims: 00000026

Ai Risk AssessmentsAmber

The proposed AIDA cross-sector AI risk-assessment framework died with Bill C-27 in January 2025 and has not been reintroduced as of this research pass.

Claims: 00000027

Biometric RegimeAmber

OPC publishes non-binding biometrics guidance; no dedicated federal or NB biometric-specific statute was confirmed.

Claims: 00000028

Genetic DataRed

No NB/federal genetic-data-specific statutory regime was located; the 23andMe genetic-data breach investigation is treated under enforcement_and_redress rather than as a distinct genetic-data statute.

State Surveillance CarveoutsRed

No state-surveillance carve-out provision specific to PIPEDA/RTIPPA/PHIPAA was retrieved in this pass.

Category narrative74 words

Canada's principal vehicle for statutory AI/ADM/biometric governance, the Artificial Intelligence and Data Act (AIDA) and the CPPA's proposed ADM-contest right, were both part of Bill C-27, which died when Parliament was prorogued on January 6, 2025; neither is currently in force. The OPC maintains non-binding guidance addressing biometrics generally. Profiling restrictions, genetic-data-specific regime, and state-surveillance carve-outs were not located as distinct provisions in this pass (the 23andMe genetic-data breach investigation is captured under enforcement_and_redress).

#

Only the education_settings sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Traffic-light rationale — RedOnly the education_settings sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Sub-modules (5)

Age VerificationRed

No PIPEDA/RTIPPA/PHIPAA age-verification-specific rule was retrieved.

Minor Profiling BansRed

No minor-specific profiling ban was retrieved under PIPEDA, RTIPPA or PHIPAA.

Education SettingsAmber

A November 2025 FPT joint resolution addresses children's/youth privacy in classroom EdTech use.

Claims: 00000029

Dependent AdultsRed

No dependent-adult-specific privacy protection was retrieved under PIPEDA, RTIPPA or PHIPAA in this pass.

Category narrative59 words

The clearest evidenced development is the November 2025 joint resolution by the federal Privacy Commissioner and provincial/territorial counterparts (including New Brunswick's) on protecting children's and youth privacy in classroom EdTech use; this is a non-binding cooperative resolution rather than a statute. Age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, and dependent-adult protections specific to PIPEDA/RTIPPA/PHIPAA were not retrieved in this pass.

#

Regulator powers, penalties, recent enforcement activity, private right of action, and 180-day developments are all well evidenced from primary OPC sources.

Primary frameworkPIPEDA ss.10.1-14 (enforcement, breach offences, Federal Court recourse)
Traffic-light rationale — GreenRegulator powers, penalties, recent enforcement activity, private right of action, and 180-day developments are all well evidenced from primary OPC sources.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

OPC refers possible offences to the Attorney General rather than prosecuting or fining directly; knowing breach-duty violations can draw fines up to $100,000.

Claims: 00000030, 00000031

Enforcement Activity IndexGreen

2025-2026 activity includes joint 23andMe and TikTok investigations and the PowerSchool breach-measures commitment.

Claims: 00000032, 00000033

Regulator Funding And CapacityRed

No specific OPC budget/headcount figures for the 2025-2026 period were retrieved in this pass.

Collective Redress And Class ActionsRed

No PIPEDA/RTIPPA/PHIPAA-specific class-action or collective-redress mechanism was retrieved in this pass (Quebec's Law 25 punitive-damages regime is a different JID and out of scope).

Private Right Of ActionGreen

PIPEDA allows Federal Court damages claims, but only following an OPC investigation and report of findings or discontinuance notice.

Claims: 00000034

Recent Developments 180DGreen

The 2025-2026 Annual Report was tabled June 4, 2026; Commissioner Dufresne became FPT co-chair in October 2025.

Claims: 00000035, 00000036

Category narrative124 words

Enforcement architecture is well documented: the OPC cannot itself levy fines or prosecute PIPEDA offences, instead referring matters to the Attorney General of Canada, while knowing violations of breach-reporting/notification/record-keeping duties can attract fines up to $100,000 through federal prosecution. Individuals have a limited private right of action to the Federal Court for damages, but only after an OPC investigation and report of findings. Recent enforcement activity includes joint investigations into 23andMe (with the UK ICO) and TikTok (with Quebec, BC and Alberta authorities), and engagement leading PowerSchool to commit to strengthened breach measures, all captured in the OPC's 2025-2026 Annual Report ('Championing privacy in the age of AI'), tabled June 4, 2026. Regulator funding/headcount specifics and collective-redress/class-action mechanisms were not retrieved in this pass.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada – New Brunswick
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 23 source(s) in the cumulative register.