What PIPEDA actually requires
PIPEDA is Canada's federal private-sector privacy law. It sets out how organisations must collect, use and disclose personal information during commercial activity, including the consent expected before dropping non-essential cookies. The law is overseen by the Office of the Privacy Commissioner of Canada (OPC).
Key requirements
- Obtain meaningful consent — implied consent is acceptable only for low-sensitivity processing
- Identify the purposes for collection before or at the time of collection
- Limit collection to what is necessary for the stated purposes
- Allow individuals to access and challenge the accuracy of their information
- Safeguard personal information with appropriate security measures
- Be open about your policies and practices
At a glance
Full name
Personal Information Protection and Electronic Documents Act
Region
Canada
Status
In force federally since 2000
Who it affects
Private-sector organisations that collect personal information during commercial activity in Canada, except where a province has substantially similar legislation (Alberta, BC, and Quebec for provincial activity).
Penalties
Fines of up to CAD 100,000 per violation for some offences. Reform proposals (Bill C-27) would significantly raise this — keep an eye on the legislative timeline.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
