🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CA-ON · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 29 sources retrieved model claude-sonnet-5 ·

Canada – Ontario

CA-ON schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 61 claims · 29 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
61Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Framework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.

Primary frameworkPIPEDA (federal, private sector) + PHIPA/FIPPA/CYFSA Part X (Ontario sectoral/public sector)
Traffic-light rationale — AmberFramework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.

Sub-modules (5)

Regulator And AuthorityGreen

OPC (federal, Gatineau HQ with a Toronto regional office) enforces PIPEDA; IPC Ontario enforces PHIPA/FIPPA/CYFSA Part X. The two regulators operate under a 2025-updated MOU enabling joint investigations.

Claims: CLM-CA-ON-a1b2c3d4, CLM-CA-ON-b2c3d4e5

Act And InstrumentsGreen

Core instruments: PIPEDA (Royal Assent 2000-04-13); PHIPA 2004; FIPPA R.S.O. 1990; CYFSA 2017 Part X.

Claims: CLM-CA-ON-c3d4e5f6

Material ScopeGreen

PIPEDA covers factual or subjective recorded/unrecorded information about an identifiable individual collected in commercial activity.

Claims: CLM-CA-ON-d4e5f6a7

Territorial ScopeGreen

PIPEDA applies to interprovincial/international transfers and to organizations doing business in/into Canada regardless of headquarters location, as confirmed by Federal Court/FCA rulings on Google's search service.

Claims: CLM-CA-ON-e5f6a7b8

Regulator Registration And FilingAmber

PIPEDA imposes no general registration/filing regime on controllers; the only affirmative filing-adjacent duty is mandatory breach record-keeping (2-year retention, producible to OPC on request).

Absence provenance: not recorded. Searched: PIPEDA controller registration requirement, Ontario PHIPA registration filing obligation.

Claims: CLM-CA-ON-f6a7b8c9

Category narrative80 words

CA-ON sits inside Canada's federated privacy architecture: the federal Office of the Privacy Commissioner of Canada (OPC) enforces PIPEDA as the general private-sector omnibus statute across Ontario (no substantially-similar provincial private-sector law exists in Ontario, unlike AB/BC/QC), while the Ontario Information and Privacy Commissioner (IPC) enforces three Ontario-specific sectoral/public statutes: PHIPA (health), FIPPA (provincial public sector access/privacy) and Part X of the CYFSA (child welfare privacy). This creates a dual-regulator, sector-stacked model rather than a single comprehensive Ontario private-sector statute.

Sources and claims (6)
  1. ConfirmedOPCThe Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.
  2. ConfirmedOPCThe Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').
  3. ConfirmedOPCPIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.
  4. ConfirmedOPCUnder PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.
  5. ConfirmedOPCThe Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.
  6. ConfirmedIAPPPIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.

#

Consent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.

Primary frameworkPIPEDA Schedule 1 (Fair Information Principles) + PHIPA (health data)
Traffic-light rationale — AmberConsent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.

Sub-modules (4)

Lawful BasesAmber

Consent is essentially the sole lawful basis for collection, use and disclosure of personal information under PIPEDA, unlike the GDPR's multiple legal bases (contract, legitimate interest, etc.).

Claims: CLM-CA-ON-a7b8c9d0

Special CategoriesAmber

PIPEDA has no codified list of special/sensitive categories; sensitivity is assessed contextually under Schedule 1. PHIPA creates Ontario's distinct statutory regime for personal health information handled by health information custodians.

Claims: CLM-CA-ON-d0e1f2a3

Pseudonymisation And AnonymisationAmber

No statutory anonymization/de-identification safe-harbour exists in PIPEDA; the Commissioner recommended strengthening the deidentification/anonymization framework as part of stalled federal reform, while IPC Ontario has issued its own updated structured-data de-identification guidelines.

Claims: CLM-CA-ON-e1f2a3b4, CLM-CA-ON-f2a3b4c5

Category narrative67 words

PIPEDA is a consent-centric regime: unlike the GDPR's multiple lawful bases, consent (express or implied, calibrated to sensitivity) is the near-exclusive gateway to collection, use and disclosure, subject to a defined list of statutory exceptions. There is no GDPR Art.9-style enumerated 'special category' regime, though PHIPA creates a distinct high-sensitivity regime for personal health information in Ontario, and CYFSA gives children in provincial care specific privacy rights.

Sources and claims (6)
  1. ConfirmedIAPPConsent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.
  2. ConfirmedOPCSection 6.1 of PIPEDA provides that consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.
  3. ConfirmedOPCSince the 2015 Digital Privacy Act amendments, organizations may disclose personal information without consent to investigate a breach of agreement/law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.
  4. ConfirmedOneTrust DataGuidanceThe IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.
  5. ProbableIAPPThe Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.
  6. ProbableOneTrust DataGuidanceThe IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.

#

Core access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.

Primary frameworkPIPEDA Schedule 1 (Principles 4.9-4.9.4) + proposed Bill C-15 data-mobility provisions
Traffic-light rationale — AmberCore access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.

Sub-modules (5)

Access RightGreen

PIPEDA Principle 4.9.4 requires organizations to respond to individual access requests within a reasonable time frame and at minimal or no cost.

Claims: CLM-CA-ON-a3b4c5d6

Rectification And ErasureAmber

PIPEDA's 'challenging compliance' principle allows individuals to dispute accuracy, but the OPC/Federal Court found no extension of accuracy obligations to underlying linked article content, leaving broad erasure/de-indexing rights unresolved.

Claims: CLM-CA-ON-b4c5d6e7

Restriction And ObjectionRed

No explicit statutory restriction-of-processing or objection-to-profiling right exists under PIPEDA in force today.

Absence provenance: not recorded. Searched: PIPEDA right to restrict processing, PIPEDA right to object profiling.

Data PortabilityAmber

Bill C-15 proposes a new Division 1.2 in PIPEDA requiring an organization, on request, to disclose an individual's collected personal information to a designated organization under a data-mobility framework — not yet in force.

Claims: CLM-CA-ON-c5d6e7f8

Deadlines And Response WindowsAmber

Access requests must be answered within a reasonable time and at minimal or no cost under Principle 4.9.4; no fixed statutory day-count deadline (e.g., 30 days) was identified for PIPEDA generally.

Claims: CLM-CA-ON-a3b4c5d6

Category narrative77 words

PIPEDA provides an access right and a 'challenging compliance' right functioning as an implicit correction mechanism, with a 'reasonable time and minimal/no cost' response standard (Principle 4.9.4). There is no explicit statutory restriction/objection right or portability right in force; a right to data mobility is only now being proposed via Bill C-15 amendments to PIPEDA. De-indexing/erasure remains contested — the OPC/Federal Court found Google's accuracy obligations do not extend to underlying linked content, leaving right-to-be-forgotten scope unresolved.

Sources and claims (3)
  1. ConfirmedOPCPrinciple 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.
  2. ConfirmedOPCAfter investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.
  3. ProbableOPCBill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.

#

Breach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).

Primary frameworkPIPEDA Schedule 1 (Accountability, Safeguards) + Breach of Security Safeguards Regulations (2018)
Traffic-light rationale — AmberBreach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).

Sub-modules (7)

Accountability And DpiaAmber

PIPEDA's accountability principle makes an organization responsible for personal information transferred to a processor; no statutory DPIA obligation exists, though the Commissioner has recommended one for high-risk activities in stalled reform.

Claims: CLM-CA-ON-d6e7f8a9, CLM-CA-ON-e7f8a9b0

Dpo RequirementsAmber

PIPEDA contains no statutory DPO-appointment threshold analogous to GDPR Art.37; Schedule 1 requires designation of an accountable individual but not a formal statutory office.

Absence provenance: not recorded. Searched: PIPEDA DPO appointment threshold, PHIPA privacy officer requirement.

Ropa RequirementsAmber

No general records-of-processing-activities obligation exists in PIPEDA; the closest analogue is the mandatory breach record-keeping duty covering all breaches regardless of harm level, retained for two years.

Claims: CLM-CA-ON-f8a9b0c1

Joint Controller ArrangementsAmber

PIPEDA treats the 'principal organization' (in control of the data) as responsible for breach reporting even where the breach occurs at a third-party processor, rather than imposing joint/several notification duties on both parties.

Claims: CLM-CA-ON-a9b0c1d2

Security MeasuresGreen

Principle 4.7 requires that personal information be protected by security safeguards appropriate to the sensitivity of the information.

Claims: CLM-CA-ON-b0c1d2e3

Breach NotificationAmber

Organizations must report to the OPC and notify affected individuals of breaches posing a 'real risk of significant harm'; the timeline standard is criticized as vague and the Commissioner has recommended a fixed 7-day reporting requirement.

Claims: CLM-CA-ON-c1d2e3f4, CLM-CA-ON-d2e3f4a5, CLM-CA-ON-e3f4a5b6

Retention And DisposalAmber

Breach records must be retained for two years and produced to the OPC upon request; no general retention-limit statute for all personal information was located.

Claims: CLM-CA-ON-f8a9b0c1

Category narrative90 words

Accountability is a foundational PIPEDA principle: organizations remain responsible for personal information transferred to third-party processors and must ensure comparable protection contractually. Statutory DPIA and DPO-appointment thresholds (GDPR Art.35/37 analogues) are absent from PIPEDA; the Commissioner has recommended a PIA requirement for high-risk processing as part of stalled reform. Breach notification is mandatory where a 'real risk of significant harm' exists, but the timeline standard ('as soon as feasible') is criticized as vague, and the OPC lacks direct fining power for breach-reporting failures (referral to the Attorney General is required).

Sources and claims (8)
  1. ConfirmedOPCPIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.
  2. ProbableIAPPThe Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.
  3. ConfirmedIAPPPIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.
  4. ConfirmedOPCThe OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.
  5. ConfirmedOPCPrinciple 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.
  6. ConfirmedOPCOrganizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.
  7. ConfirmedOPCSignificant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.
  8. ProbableOPCPIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.

#

Adequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.

Primary frameworkPIPEDA (no dedicated transfer chapter) + EU Commission Decision 2002/2/EC as reviewed 2024
Traffic-light rationale — AmberAdequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.

Sub-modules (6)

Transfer MechanismsAmber

PIPEDA does not contain separate and explicit rules governing trans-border data flows; instead it requires transparency about foreign processing and requires organizations to ensure a comparable level of protection via contractual or other means for third-party processing.

Claims: CLM-CA-ON-f4a5b6c7, CLM-CA-ON-a5b6c7d8

Adequacy ReceivedGreen

Not applicable in the outbound sense for CA-ON as a receiving jurisdiction from the EU; see adequacy_granted for Canada's inbound adequacy from the EU.

Adequacy GrantedGreen

The European Commission concluded in January 2024 that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA, as part of an 11-jurisdiction periodic adequacy review; the UK separately maintains its own adequacy regulations covering PIPEDA-subject recipients.

Claims: CLM-CA-ON-b6c7d8e9, CLM-CA-ON-c7d8e9f0, CLM-CA-ON-d8e9f0a1

Sccs And BcrsAmber

PIPEDA has no dedicated SCC/BCR statutory mechanism; where adequacy does not apply (e.g., non-federally-regulated employee data or intra-provincial data outside PIPEDA's ambit), practitioners rely on contractual safeguards akin to SCCs, and the OPC is exploring the Global CBPR Forum as a further certification-based mechanism.

Claims: CLM-CA-ON-e9f0a1b2, CLM-CA-ON-f0a1b2c3

Transfer Impact AssessmentAmber

No statutory TIA requirement equivalent to Schrems II practice was identified as a formal PIPEDA obligation; risk-assessment practice is industry-guidance-driven rather than legislated.

Absence provenance: not recorded. Searched: PIPEDA transfer impact assessment requirement, OPC TIA guidance PIPEDA.

Data LocalisationGreen

No general data-localisation mandate was identified under PIPEDA or Ontario's sectoral statutes.

Absence provenance: not recorded. Searched: PIPEDA data localisation requirement, Ontario PHIPA data residency requirement.

Category narrative87 words

PIPEDA contains no separate explicit trans-border data flow rules; instead it relies on transparency and accountability obligations requiring comparable protection when data is transferred abroad for processing. Canada (for PIPEDA-covered commercial operators) holds a long-standing EU adequacy decision, most recently reconfirmed in the Commission's January 2024 periodic review, with the next review expected around 2028; the UK separately recognizes PIPEDA-covered transfers via its own adequacy regulations. Adequacy is partial: it excludes the substantially-similar provincial regimes of Alberta, British Columbia and Quebec, and generally excludes non-federally-regulated employee data.

Sources and claims (7)
  1. ConfirmedOPCPIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.
  2. ConfirmedOPCPIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.
  3. ConfirmedEUR-LexOn January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.
  4. ProbableOPCCanada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.
  5. ConfirmedIAPPCanada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.
  6. ProbableOPCThe Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.
  7. ProbableOPCThe Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.

#

Health sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.

Primary frameworkPHIPA (health) + CASL (telecoms/e-marketing) + PIPEDA (federally-regulated employment)
Traffic-light rationale — AmberHealth sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.

Sub-modules (7)

Financial Sector OverlayAmber

Federally-regulated banks are directly subject to PIPEDA as federal works, undertakings or businesses (FWUBs); no distinct Ontario provincial financial-sector privacy overlay was identified.

Claims: CLM-CA-ON-a1c3e5g7

Health Sector OverlayGreen

PHIPA governs personal health information handled by Ontario health information custodians, administered by the IPC, and has been declared substantially similar to PIPEDA for health information purposes; the IPC has now issued its first monetary penalties under PHIPA.

Claims: CLM-CA-ON-b2d4f6h8, CLM-CA-ON-c3e5g7i9

Telecoms And EprivacyGreen

CASL, the federal anti-spam law, is jointly enforced by the CRTC, OPC and Competition Bureau and separately amended PIPEDA regarding electronic address harvesting.

Claims: CLM-CA-ON-d4f6h8j0

Employment DataRed

There is currently no privacy legislation applicable to non-federally-regulated Ontario employees; PIPEDA only covers employees/applicants of federally-regulated employers (FWUBs), a gap FPT Commissioners have formally flagged.

Claims: CLM-CA-ON-e5g7i9k1, CLM-CA-ON-f6h8j0l2

Credit And ScoringRed

No distinct Ontario or federal credit-scoring-specific data protection statute was located in this research pass.

Absence provenance: not recorded. Searched: Ontario credit scoring privacy law, PIPEDA credit reporting data rules.

EducationAmber

Ontario schools/universities are generally covered by provincial (FIPPA/MFIPPA) rather than PIPEDA rules, and Canadian privacy regulators have jointly resolved to strengthen children's privacy protections in EdTech.

Claims: CLM-CA-ON-g7i9k1m3, CLM-CA-ON-h8j0l2n4

InsuranceRed

No distinct Ontario or federal insurance-sector data protection overlay was located in this research pass; general PIPEDA/PHIPA rules would apply by default.

Absence provenance: not recorded. Searched: Ontario insurance sector privacy law, PIPEDA insurance data rules.

Category narrative81 words

Ontario's sectoral overlays are concentrated in health (PHIPA, with a mature IPC administrative-monetary-penalty regime now in active use) and public-sector/child-welfare (FIPPA, CYFSA), while general private-sector employment privacy remains a documented statutory gap outside AB/BC/QC — non-federally-regulated Ontario employees have no dedicated statutory privacy protection distinct from PIPEDA, which itself only covers federally-regulated employers' employees/applicants. Telecoms/e-marketing is separately regulated federally via CASL (CRTC/OPC/Competition Bureau shared enforcement). No distinct Ontario/federal statutory regime for credit-scoring or insurance-sector data was located in this research pass.

Sources and claims (8)
  1. ConfirmedOPCFederally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.
  2. ConfirmedOneTrust DataGuidanceThe Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.
  3. ConfirmedOneTrust DataGuidanceThe IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.
  4. ConfirmedOPCAt the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.
  5. ConfirmedOPCThere is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.
  6. ConfirmedOPCCanada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.
  7. ConfirmedOPCMunicipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.
  8. ProbableOneTrust DataGuidanceCanadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

#

Direct marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.

Primary frameworkCASL + PIPEDA (address harvesting provisions)
Traffic-light rationale — AmberDirect marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.

Sub-modules (6)

Cookies And TrackersAmber

No CA-ON-specific cookie-consent statute (ePrivacy-style) was located; general PIPEDA consent principles apply to tracking technologies by default.

Absence provenance: not recorded. Searched: Ontario cookie consent law, PIPEDA cookie tracking rules.

Dark PatternsAmber

The OPC provides guidance on deceptive design patterns that may influence individuals into giving away more personal information online, though this is guidance rather than a standalone dark-patterns statute.

Claims: CLM-CA-ON-i9k1m3o5

Opt Out SignalsRed

No statutory recognition of browser-based opt-out signals (e.g., Global Privacy Control) was located under PIPEDA or Ontario statutes.

Absence provenance: not recorded. Searched: PIPEDA Global Privacy Control recognition, Ontario opt-out signal law.

Clean Rooms And DcrRed

No Canadian federal or Ontario-specific clean-room/data-collaboration-room regulatory framework was located.

Absence provenance: not recorded. Searched: Canada data clean room regulation, PIPEDA data collaboration room rules.

Cross Context AdvertisingAmber

PIPEDA has no CPRA-style 'sale'/'share' distinction for cross-context advertising; consent-based rules apply generally to disclosure for advertising purposes.

Absence provenance: not recorded. Searched: PIPEDA cross-context advertising rules, Canada sale of personal information advertising rules.

Direct MarketingGreen

CASL requires express or implied consent, sender identification and unsubscribe mechanisms for commercial electronic messages; implied consent based on an existing business relationship expires after two years; PIPEDA separately prohibits address harvesting with very limited exceptions.

Claims: CLM-CA-ON-j0l2n4p6, CLM-CA-ON-k1m3o5q7, CLM-CA-ON-l2n4p6r8

Category narrative84 words

Direct marketing/commercial electronic messaging is governed federally by CASL (jointly enforced by CRTC, OPC and Competition Bureau) requiring express or implied consent, sender identification and functioning unsubscribe mechanisms; implied consent from an 'existing business relationship' expires after two years. PIPEDA separately prohibits address harvesting. CRTC enforcement precedent (CompuFinder, $1.1M AMP) demonstrates meaningful sectoral penalty capacity despite PIPEDA itself lacking fining power. No dedicated statutory framework for opt-out signals (e.g., Global Privacy Control), clean rooms/data-collaboration rooms, or cross-context-advertising 'sale/share' concepts (CPRA-style) was located for CA-ON.

Sources and claims (4)
  1. ConfirmedOPCThe OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.
  2. ConfirmedIAPPCASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.
  3. ConfirmedIAPPImplied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.
  4. ConfirmedOPCWith very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.

#

No comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.

Primary frameworkNone in force (AIDA/CPPA died with Bill C-27, 2025) — governed ad hoc via PIPEDA general principles and IPC/OPC guidance
Traffic-light rationale — RedNo comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.

Sub-modules (6)

Profiling RestrictionsRed

No statutory Art.22-style profiling restriction is in force in Canada; the stalled CPPA would have introduced algorithmic transparency provisions.

Claims: CLM-CA-ON-m3o5q7s9

Automated Decision Making TransparencyRed

The proposed (now-stalled) CPPA would have provided algorithmic transparency and a right of individuals to obtain an explanation of automated decisions; this is not currently in force.

Claims: CLM-CA-ON-n4p6r8t0

Ai Risk AssessmentsRed

AIDA, Canada's first attempt at cross-sector AI risk-assessment legislation for high-impact systems, died with Bill C-27's failure to pass before Parliament's January 2025 prorogation and has not been reintroduced.

Claims: CLM-CA-ON-o5q7s9u1, CLM-CA-ON-p6r8t0v2

Biometric RegimeAmber

The OPC is finalizing guidance on biometrics for public and private sector organizations following a fall 2023/winter 2024 public consultation; no standalone biometric statute exists.

Claims: CLM-CA-ON-q7s9u1w3

Genetic DataAmber

No standalone genetic-data statute was located; the IPC has published 12 guardrails specifically for police use of investigative genetic genealogy, addressing privacy and human-rights concerns.

Claims: CLM-CA-ON-r8t0v2x4

State Surveillance CarveoutsAmber

Detailed evidence on national-security carve-outs specific to CA-ON was not located in this research pass; general federal Privacy Act national-security exemptions are understood to exist but require further primary-source verification.

Absence provenance: not recorded. Searched: Canada national security privacy exemption Ontario, PIPEDA law enforcement disclosure exemption scope.

Category narrative104 words

Canada currently has no comprehensive federal AI statute in force: the Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died when Parliament was prorogued on January 6, 2025, and has not been reintroduced as of this research pass. Algorithmic-transparency/ADM-explanation rights were only proposed (via the stalled CPPA) and are not currently in force. The OPC is finalizing biometrics guidance following a 2023-2024 consultation, and Ontario's IPC has been highly active on AI/biometric governance specifically — co-issuing AI-use principles with the Ontario Human Rights Commission, publishing 12 guardrails for police use of investigative genetic genealogy, and joining a multi-provincial investigation into OpenAI's ChatGPT.

Sources and claims (6)
  1. ProbableIAPPThe CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.
  2. ProbableIAPPPIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.
  3. ConfirmedOneTrust DataGuidanceThe prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.
  4. ProbableIAPPAs of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.
  5. ProbableOPCThe OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.
  6. ProbableOneTrust DataGuidanceOntario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.

#

A concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.

Primary frameworkCYFSA Part X (children in care) + PIPEDA general consent principles
Traffic-light rationale — AmberA concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.

Sub-modules (5)

Age VerificationRed

No statutory age-verification threshold was located for CA-ON; PIPEDA applies contextual consent standards rather than a fixed age threshold.

Absence provenance: not recorded. Searched: PIPEDA age of consent minors, Ontario age verification statute.

Minor Profiling BansRed

No statutory minor-specific profiling ban was located; the stalled CPPA reform was criticized by commentators for not going far enough on protecting children's/youth privacy.

Claims: CLM-CA-ON-s9u1w3y5

Education SettingsAmber

Canadian federal/provincial/territorial privacy commissioners issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

Claims: CLM-CA-ON-t0v2x4z6

Dependent AdultsRed

No dependent-adult-specific privacy protection regime was located for CA-ON in this research pass.

Absence provenance: not recorded. Searched: Ontario dependent adult privacy protection law, PIPEDA elderly incapacity data protection.

Category narrative77 words

Ontario's most direct statutory protection for a vulnerable group is Part X of the CYFSA, which gives children in the child-welfare system a right to reasonable privacy and possession of personal property. Federal/provincial commissioners have jointly targeted children's privacy in EdTech and flagged that stalled federal reform (CPPA) did not go far enough on children's/youth privacy. No age-verification or COPPA/GDPR-Art.8-style parental-consent threshold statute was located for CA-ON in this research pass; dependent-adult-specific protections were similarly not identified.

Sources and claims (2)
  1. ProbableIAPPCommentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.
  2. ProbableOneTrust DataGuidanceCanadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

#

Ontario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.

Primary frameworkPIPEDA enforcement provisions (ss.11-17, s.28) + PHIPA s.61.1 AMP regime
Traffic-light rationale — AmberOntario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The OPC cannot prosecute PIPEDA offences or issue fines directly, but can refer possible offences to the Attorney General for prosecution by the Director of Public Prosecutions; the IPC, by contrast, has direct AMP power under PHIPA up to CAD 500,000 for organizations.

Claims: CLM-CA-ON-u1w3y5a7, CLM-CA-ON-v2x4z6b8, CLM-CA-ON-w3y5a7c9

Enforcement Activity IndexAmber

The OPC closed 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26 amid a significant rise in complaint volumes; the IPC issued its first-ever PHIPA monetary penalties in the same period.

Claims: CLM-CA-ON-x4z6b8d0, CLM-CA-ON-y5a7c9e1

Regulator Funding And CapacityAmber

The Commissioner has stressed the need for stable, permanent OPC funding to keep pace with growing complexity of privacy issues, having previously operated on temporary funding.

Claims: CLM-CA-ON-z6b8d0f2

Collective Redress And Class ActionsAmber

No dedicated statutory class-action mechanism specific to PIPEDA/PHIPA was independently confirmed in this pass; case law (e.g., Hopkins v. Kay) has permitted individual civil suits for PHIPA breaches, suggesting a common-law avenue exists alongside statutory complaint processes.

Claims: CLM-CA-ON-a7c9e1g3

Private Right Of ActionAmber

CASL originally contemplated a private right of action for contraventions, planned to come into force in a later implementation phase; current operative status requires primary-source confirmation.

Absence provenance: not recorded. Searched: CASL private right of action current status 2026.

Claims: CLM-CA-ON-b8d0f2h4

Recent Developments 180DGreen

Within the last ~180 days: Commissioner Dufresne testified on Bill C-15's PIPEDA data-mobility amendments before House INDU (Jan 2026) and Senate committees; the OPC/Quebec/BC/Alberta joint OpenAI ChatGPT investigation concluded (May 2026); Dufresne was elected Chair of the Global Privacy Assembly; and the OPC-IPC MOU continues to enable cross-statute joint investigations.

Claims: CLM-CA-ON-c9e1g3i5, CLM-CA-ON-d0f2h4j6, CLM-CA-ON-e1g3i5k7

Category narrative122 words

Enforcement is bifurcated: the federal OPC operates largely as an ombudsman under PIPEDA with no direct order-making or fining power — it can investigate, issue findings, refer offences to the Attorney General for prosecution, or seek a Federal Court order (application window extended from 45 days to one year) — while Ontario's IPC has direct administrative-monetary-penalty power under PHIPA (up to CAD 500,000 for organizations) and has now used it for the first time. The OPC saw a significant rise in complaint volumes in FY2025-26. Recent developments (within ~180 days) include Bill C-15's proposed PIPEDA data-mobility amendments (Commissioner testimony January-February 2026), the concluded joint OPC/Quebec/BC/Alberta investigation into OpenAI's ChatGPT (May 2026), and the Commissioner's election as Chair of the Global Privacy Assembly.

Sources and claims (11)
  1. ConfirmedOPCThe OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.
  2. ConfirmedOPCThe time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.
  3. ConfirmedOneTrust DataGuidanceFollowing amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.
  4. ConfirmedOPCThe OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.
  5. ConfirmedOPCThe OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.
  6. ProbableIAPPThe Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.
  7. ProbableOneTrust DataGuidanceIn Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.
  8. UncertainIAPPCASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).
  9. ConfirmedOPCIn January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.
  10. ConfirmedOPCThe Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.
  11. ConfirmedOPCCommissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Canada – Ontario
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 61 claim(s), 29 source(s) in the cumulative register.