Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Privacy rights in Canada have entered a new era. With Quebec's Law 25 fully in force, the long-awaited federal reform tabled through Bill C-27, and provincial regulators becoming more assertive, 2026 is a pivotal year for how personal information is collected, used, and protected. This guide breaks down what individuals and organisations across Canada need to know, from consent standards to breach reporting, cross-border transfers, and everyday steps to safeguard your data.
The Canadian Privacy Landscape in 2026
Canadian privacy law is a patchwork of federal, provincial, and sector-specific statutes. At the federal level, the Personal Information Protection and Electronic Documents Act (PIPEDA) still governs most private-sector activity, while the Privacy Act covers federal government institutions. Several provinces — notably Quebec, Alberta, and British Columbia — have their own private-sector laws that regulators consider "substantially similar" to PIPEDA.
In 2026, three forces are reshaping the landscape:
- Quebec's Law 25 is now fully operational, including the data portability right that came into effect in September 2024.
- Federal reform through the Consumer Privacy Protection Act (CPPA) and the Artificial Intelligence and Data Act (AIDA), packaged in Bill C-27, is progressing through Parliament.
- Regulator enforcement from the Office of the Privacy Commissioner of Canada (OPC) and provincial counterparts is increasingly coordinated and public.
Your Core Privacy Rights Under PIPEDA
PIPEDA grants individuals a set of foundational rights whenever a private-sector organisation collects, uses, or discloses personal information in the course of commercial activity. Personal information is defined broadly: any information about an identifiable individual, from names and email addresses to browsing behaviour and biometric identifiers.
1. The Right to Meaningful Consent
Organisations must obtain meaningful consent before collecting or using your data. In 2026, the OPC expects consent requests to be written in plain language, clearly identify the purposes, and disclose any third parties who will receive the information. Consent bundled deep inside a 30-page terms document is unlikely to be considered valid.
2. The Right to Access and Correct
You can ask any organisation what personal information they hold about you, how it is being used, and to whom it has been disclosed. They must respond within 30 days, generally at no cost. If the information is inaccurate, you have the right to have it corrected.
3. The Right to Withdraw Consent
Consent is not permanent. Individuals may withdraw consent at any time, subject to legal or contractual restrictions, and organisations must inform them of the consequences before processing the withdrawal.
4. The Right to Complain
If an organisation refuses to comply, you can file a complaint with the OPC or the applicable provincial commissioner. Regulators can investigate, publish findings, and — under Quebec's Law 25 and the proposed CPPA — impose significant financial penalties.
Quebec's Law 25: Canada's Strictest Regime
Law 25 (formerly Bill 64) modernised Quebec's private-sector privacy law and now sets the highest bar in Canada. Any organisation that handles personal information about Quebec residents — regardless of where the business is located — must comply.
Key Obligations Under Law 25
- Privacy Officer: Every organisation must designate a person responsible for the protection of personal information, and publish their contact details.
- Privacy Impact Assessments (PIAs): Required before implementing information system projects, acquiring technology, or transferring data outside Quebec.
- Confidentiality by default: Products and services with privacy settings must be configured to the highest privacy level by default.
- Data portability: Individuals can request their data in a structured, commonly used technological format.
- Automated decision-making transparency: Organisations must inform individuals when a decision is based exclusively on automated processing and offer the ability to submit observations.
Penalties Under Law 25
Administrative monetary penalties can reach the greater of CAD $10 million or 2% of worldwide turnover. Penal offences can climb to CAD $25 million or 4% of worldwide turnover — figures that put Quebec on par with the EU's GDPR.
Federal Reform: The CPPA and AIDA
Bill C-27 proposes to replace PIPEDA's private-sector provisions with the Consumer Privacy Protection Act and to introduce the Artificial Intelligence and Data Act. While the legislative timeline continues to shift, the direction of travel is clear.
What Would Change Under the CPPA
- Explicit right to disposal (deletion) of personal information.
- Enhanced algorithmic transparency for automated decision systems.
- Special protections for minors' data, treated as sensitive by default.
- A new Personal Information and Data Protection Tribunal to hear appeals and impose fines.
- Maximum penalties of up to 5% of global revenue or CAD $25 million, whichever is greater.
Comparing the Major Canadian Privacy Frameworks
| Feature | PIPEDA (Federal) | Quebec Law 25 | Proposed CPPA |
|---|---|---|---|
| Right to deletion | Limited | Yes (right to de-indexation) | Yes (right to disposal) |
| Data portability | No | Yes (in force) | Yes (proposed) |
| Privacy Impact Assessments | Recommended | Mandatory | Mandatory for high-risk uses |
| Automated decision transparency | No | Yes | Yes |
| Maximum penalty | CAD $100,000 | 4% of global turnover | 5% of global revenue |
| Breach notification | Mandatory (real risk of significant harm) | Mandatory | Mandatory |
Data Breach Notification Requirements
Canada requires organisations to notify affected individuals and regulators when a breach of security safeguards creates a "real risk of significant harm." Under PIPEDA, notification must occur "as soon as feasible." Records of every breach — regardless of severity — must be kept for at least 24 months.
Steps to Take After a Breach
- Contain the incident and preserve evidence.
- Assess the sensitivity of the data and the probability of misuse.
- Notify the OPC and/or provincial commissioner if the risk threshold is met.
- Inform affected individuals with clear guidance on how to mitigate harm.
- Document the incident, response, and remediation steps.
Cross-Border Data Transfers
Cross-border transfers remain lawful under Canadian law, but they come with strings attached. Under Law 25, organisations must conduct a PIA before transferring personal information outside Quebec and confirm that the receiving jurisdiction offers "adequate" protection. Federally, PIPEDA treats transfers as a "use" of data — meaning the transferring organisation remains accountable regardless of where the data lives.
Practical steps for compliant transfers include contractual safeguards, encryption in transit and at rest, vendor due diligence, and transparency notices explaining where data may be processed.
Workplace Privacy Rights in 2026
Employee monitoring has expanded with remote and hybrid work, and privacy commissioners have responded. Federally regulated employers and Ontario employers with 25+ workers must have written electronic monitoring policies. Quebec goes further: any monitoring technology that could identify or track an employee triggers PIA obligations and transparency notices.
What Employees Should Expect
- A written policy explaining what is monitored and why.
- Notice before new monitoring tools are introduced.
- The ability to access their own employment file.
- Limits on the collection of biometric information without express consent.
Children and Youth Privacy
Regulators increasingly treat children's data as inherently sensitive. The OPC's guidance and Quebec's Law 25 both require enhanced consent standards, and the proposed CPPA would codify heightened protections for minors under 18. Platforms directed at youth are expected to implement age-appropriate design, minimise data collection, and default to the most protective settings.
Practical Steps to Protect Your Privacy
Legal rights matter, but everyday habits determine how much personal information ends up in circulation. In 2026, Canadians can meaningfully reduce their exposure with a handful of practical measures.
For Individuals
- Audit your accounts. Review which apps and services still have access to your email, calendar, contacts, and location.
- Use encrypted DNS and privacy-focused browsers. Tools like DNS-over-HTTPS and browsers with built-in tracker blocking prevent much of the passive data collection that happens in the background.
- Turn on multi-factor authentication for email, banking, and any account tied to your identity.
- Watch what you click. Shortened links can hide malicious destinations. Reputable link management services such as Lunyb offer link previews and analytics without harvesting personal browsing data — a safer alternative to opaque redirectors.
- Exercise your access rights. Ask major platforms for a copy of your data at least once a year; you may be surprised what is stored.
For Businesses
- Map the personal information you collect, where it flows, and who has access.
- Appoint a privacy officer and publish their contact details.
- Adopt a documented breach response plan and rehearse it.
- Conduct PIAs for new tools, especially anything involving analytics, AI, or cross-border transfers.
- Update privacy notices in plain language and refresh consent mechanisms.
For teams that rely on shortened links in marketing campaigns, choosing a compliant provider matters. Our 2026 comparison of the best URL shorteners covers privacy features to look for, and our honest review of Lunyb explains how it handles user data. If you are evaluating enterprise options, our Rebrandly review is a useful reference point.
Enforcement Trends to Watch in 2026
The OPC has signalled a more assertive posture: joint investigations with provincial commissioners, deeper scrutiny of AI systems, and public findings that name organisations. Quebec's Commission d'accès à l'information (CAI) has begun issuing administrative penalties under Law 25, and Ontario continues to consider a private-sector privacy law of its own. Businesses should assume that non-compliance now carries both financial and reputational risk.
Frequently Asked Questions
Do I have a "right to be forgotten" in Canada?
Not in the same form as under the EU's GDPR. However, Quebec's Law 25 introduced a right to de-indexation and cessation of dissemination, and the proposed federal CPPA includes a right to disposal (deletion) of personal information. PIPEDA today provides limited deletion rights, mostly tied to withdrawal of consent.
Does Canadian privacy law apply to foreign companies?
Yes. If a foreign organisation collects personal information from individuals in Canada in the course of commercial activity — for example, through a website or app — Canadian law generally applies. Quebec's Law 25 explicitly reaches organisations outside Quebec that handle information about Quebec residents.
How quickly must a data breach be reported?
Under PIPEDA, notification to the OPC and affected individuals must occur "as soon as feasible" after determining that a breach creates a real risk of significant harm. Provincial rules in Quebec, Alberta, and elsewhere follow similar timelines. Records of every breach must be retained for at least 24 months.
What are the penalties for non-compliance in 2026?
Under current PIPEDA, fines are capped at CAD $100,000 per offence. Quebec's Law 25 allows administrative penalties up to 2% of global turnover and penal fines up to 4%. The proposed CPPA would raise maximum federal penalties to 5% of global revenue or CAD $25 million, whichever is greater.
Can my employer monitor my work computer?
Generally yes, but with limits. Employers must have a legitimate purpose, provide notice through a written policy, and collect only what is necessary. Federally regulated employers, Ontario employers with 25+ employees, and Quebec employers face specific written-policy and transparency requirements. Covert monitoring without notice is rarely justifiable.
The Bottom Line
Privacy in Canada is no longer a light-touch regime. Quebec has moved to a European-style framework, federal reform is advancing, and regulators are willing to name organisations and impose meaningful penalties. For individuals, 2026 offers stronger tools — access, correction, portability, and, in Quebec, de-indexation — to take control of personal information. For businesses, the message is equally clear: treat privacy as a core operational discipline, not a compliance afterthought. The organisations that build trust through transparent, minimised, and well-governed data practices will be the ones that thrive in Canada's new privacy era.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data — from access and correction to data portability and breach notifications. This 2026 guide explains every right, how to exercise it, and what businesses must do to stay compliant.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
Brexit didn't scrap GDPR in the UK — it created a parallel regime called UK GDPR. This guide explains what changed, how UK GDPR compares to EU GDPR, and the practical steps businesses must take on international transfers, representatives and compliance in 2026.
Data Protection Act 2018 Ireland: Complete Guide for Businesses
A complete, practical guide to the Data Protection Act 2018 in Ireland — covering its scope, principles, individual rights, DPC enforcement, breach notifications, and compliance steps for Irish businesses. Learn how to align your organisation with Ireland's data protection framework and avoid costly penalties.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission. Learn your GDPR rights, prepare strong evidence, and understand what to expect from the DPC investigation process.