facebook-pixel

Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses

L
Lunyb Security Team
··10 min read

Privacy rights in Canada have entered a new era in 2026. With the ongoing modernisation of federal legislation, the growing weight of provincial regimes in Quebec, British Columbia, and Alberta, and heightened public awareness after several high-profile data breaches, Canadians now enjoy stronger — and more clearly defined — protections than at any point in the country's history. This guide breaks down what those rights actually mean, how they are enforced, and what individuals and organisations must do to stay compliant.

What Are Privacy Rights in Canada?

Privacy rights in Canada are the legal protections that give individuals control over how their personal information is collected, used, disclosed, and stored by governments, businesses, and other organisations. These rights are grounded in a combination of federal statutes, provincial laws, common law torts, and the Canadian Charter of Rights and Freedoms.

In 2026, the Canadian privacy framework rests on four main pillars:

  1. The Privacy Act — governs federal government institutions.
  2. PIPEDA (Personal Information Protection and Electronic Documents Act) — governs private-sector organisations engaged in commercial activity.
  3. Provincial privacy laws — including Quebec's Law 25, Alberta's PIPA, and British Columbia's PIPA.
  4. Sector-specific rules — covering health information, credit reporting, and telecommunications.

Together, these laws create a layered system where Canadians have the right to know what data is collected about them, to access and correct it, to withdraw consent, and — increasingly — to have their information deleted.

The Federal Framework: PIPEDA and the Road to Bill C-27

PIPEDA has been Canada's central private-sector privacy law since 2000. It applies to any organisation that collects, uses, or discloses personal information in the course of commercial activity across provincial or national borders. PIPEDA is built around ten fair information principles, including accountability, consent, limiting collection, accuracy, and individual access.

Bill C-27 and the Consumer Privacy Protection Act

Bill C-27, the Digital Charter Implementation Act, continues to reshape Canada's privacy landscape in 2026. It proposes to replace parts of PIPEDA with three new statutes:

  • The Consumer Privacy Protection Act (CPPA) — modernises consent rules, introduces a right to data mobility, and strengthens protections for minors.
  • The Personal Information and Data Protection Tribunal Act — creates a specialised tribunal to review Privacy Commissioner decisions and impose penalties.
  • The Artificial Intelligence and Data Act (AIDA) — establishes obligations for high-impact AI systems, including risk assessments and transparency requirements.

Under the CPPA, administrative monetary penalties can reach up to 3% of global revenue or C$10 million, and the most serious offences can trigger fines of up to 5% of global revenue or C$25 million — bringing Canada closer to the European GDPR in terms of enforcement teeth.

Key Rights Under the Federal Regime

  1. Right to know what personal information an organisation holds about you and how it is used.
  2. Right of access to your data and the ability to request corrections.
  3. Right to withdraw consent at any time, subject to legal or contractual restrictions.
  4. Right to data portability (expanded under the CPPA) to move your data between service providers.
  5. Right to erasure — request deletion of personal information no longer needed for its original purpose.
  6. Right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC).

Provincial Privacy Laws in 2026

Three provinces — Quebec, Alberta, and British Columbia — have private-sector privacy laws deemed substantially similar to PIPEDA, meaning they apply instead of the federal law within their borders for provincially regulated organisations.

Quebec's Law 25

Quebec's Law 25 (formerly Bill 64) is now fully in force and remains the most stringent privacy regime in Canada. Its highlights include mandatory privacy impact assessments, appointment of a Chief Privacy Officer, explicit consent for sensitive information, transparency around automated decision-making, and a genuine right to data portability. Penalties reach C$25 million or 4% of worldwide turnover.

Alberta and British Columbia PIPA

Both provinces' Personal Information Protection Acts closely mirror PIPEDA but include local nuances, particularly around employee personal information — an area federal PIPEDA covers only for federally regulated workplaces.

Health Sector Legislation

Health information is regulated separately under statutes like Ontario's PHIPA, Alberta's HIA, and similar frameworks in every province. These laws impose strict duties on custodians of health data and grant patients enhanced rights of access and correction.

Comparing Canada's Major Privacy Laws

FeaturePIPEDA (Federal)Quebec Law 25Alberta/BC PIPA
ScopeCommercial activity across CanadaAll Quebec organisationsProvincially regulated organisations
ConsentMeaningful consent requiredExpress consent for sensitive dataKnowledge and consent required
Breach notificationMandatory (real risk of significant harm)MandatoryMandatory (Alberta), voluntary in some BC cases
Data portabilityComing under CPPAYes (fully in force)Limited
Maximum finesUp to C$100k (proposed C$25M under CPPA)Up to C$25M or 4% of turnoverUp to C$100k (individuals lower)
Privacy officer requiredYesYes (Chief Privacy Officer)Yes

Consumer Rights in Everyday Digital Life

Canadian privacy law is not just about compliance paperwork — it directly shapes daily interactions with apps, websites, retailers, and government services. In 2026, Canadians can expect the following practical protections:

Transparent Privacy Notices

Organisations must provide clear, plain-language privacy policies. Under Quebec's Law 25 and the incoming CPPA, notices must be understandable to a reasonable person and, when directed at minors, adapted to their level of comprehension.

Cookie and Tracking Consent

While Canada does not have a dedicated "cookie law" like the EU's ePrivacy Directive, tracking technologies that collect personal information require meaningful consent under PIPEDA and Law 25. Expect to see more granular consent banners on Canadian websites throughout 2026.

Automated Decision-Making

If an organisation uses AI or algorithms to make a decision that significantly affects you — such as credit scoring, insurance pricing, or hiring — you have the right to be informed and, in Quebec, to request human review.

Marketing and Anti-Spam Rules

Canada's Anti-Spam Legislation (CASL) continues to require express or implied consent before sending commercial electronic messages. Violations can lead to penalties of up to C$10 million per incident for organisations.

What Organisations Must Do in 2026

Businesses operating in Canada — regardless of size — face a rising compliance bar. The following steps are now considered baseline practice:

  1. Appoint a privacy officer whose contact information is publicly available.
  2. Maintain a data inventory covering what personal information is collected, why, where it is stored, and who has access.
  3. Conduct privacy impact assessments (PIAs) for new projects involving sensitive data, cross-border transfers, or automated decisions.
  4. Update privacy policies to reflect Law 25, CPPA readiness, and AIDA obligations where relevant.
  5. Implement breach response procedures, including OPC notification and record-keeping.
  6. Vet third-party processors with contractual safeguards for data handling and cross-border transfers.
  7. Train employees on privacy fundamentals and internal reporting channels.

Cross-Border Data Transfers

Canada does not require data localisation federally, but organisations must inform individuals when their information may be processed outside the country. Quebec's Law 25 requires a privacy impact assessment before any transfer outside the province, weighing the legal framework of the destination jurisdiction.

How Canadians Can Exercise Their Privacy Rights

Understanding your rights is only half the battle — knowing how to use them matters just as much. Here is a step-by-step approach:

  1. Start with the organisation. Contact its designated privacy officer in writing to request access, correction, or deletion of your data.
  2. Wait for a response. Under PIPEDA, organisations generally have 30 days to respond. Law 25 also imposes a 30-day timeline.
  3. Escalate if needed. File a complaint with the OPC federally, or with the Commission d'accès à l'information (Quebec), the Office of the Information and Privacy Commissioner (Alberta/BC), or the equivalent provincial body.
  4. Consider civil remedies. Canadian courts increasingly recognise privacy torts such as "intrusion upon seclusion" and "public disclosure of private facts," allowing individuals to sue for damages.

Practical Privacy Tips for Canadians in 2026

Beyond formal legal rights, everyday habits play a huge role in protecting personal information. Consider these practical steps:

  • Use strong, unique passwords stored in a reputable password manager.
  • Enable multi-factor authentication on financial, email, and government accounts.
  • Prefer encrypted DNS resolvers and privacy-respecting browsers that block third-party trackers.
  • Review app permissions on your phone every few months and revoke anything unnecessary.
  • Be cautious when clicking shortened links — use a trustworthy shortener that discloses how it handles click data. For example, Lunyb is a Canadian-friendly URL shortener designed with privacy in mind, and you can also compare it against alternatives in our 2026 buyer's guide.
  • Read privacy notices before signing up for new services — especially those aimed at children or teenagers.
  • Request annual data disclosures from companies you use frequently to see what they hold.

The Role of the Office of the Privacy Commissioner

The Office of the Privacy Commissioner of Canada (OPC) remains the central federal enforcement body. In 2026, its priorities include artificial intelligence and generative models, children's privacy, biometric technologies, and cross-border data flows. The OPC also publishes practical guidance, investigates complaints, and can now recommend penalties through the new tribunal once Bill C-27 is fully operational.

Provincial commissioners play equivalent roles and often collaborate on joint investigations. For instance, the OPC and Quebec's Commission d'accès à l'information have issued coordinated findings against major tech platforms in recent years.

Emerging Issues to Watch in 2026 and Beyond

Several developments are likely to shape Canadian privacy over the next 12 to 24 months:

  • AI regulation. Once AIDA is finalised, high-impact AI systems will face mandatory risk assessments, transparency obligations, and potential prohibitions on harmful uses.
  • Biometric data. Both federal and provincial regulators are scrutinising facial recognition, workplace monitoring, and voiceprint technologies.
  • Children's privacy. The CPPA treats minors' information as sensitive by default, and Quebec already requires enhanced protections.
  • Data broker transparency. Expect further guidance — and possibly new legislation — around the sale and profiling of personal information.
  • Interoperability with global regimes. Canada continues to align gradually with the EU's GDPR to preserve its "adequacy" status for cross-border transfers.

Frequently Asked Questions

Is PIPEDA still the main privacy law in Canada in 2026?

Yes. Until Bill C-27 is fully passed and in force, PIPEDA remains the primary federal private-sector privacy law. The proposed Consumer Privacy Protection Act (CPPA) is expected to replace parts of PIPEDA and significantly increase penalties, but organisations should continue complying with PIPEDA in the meantime and prepare for the transition.

Do I have a right to have my personal data deleted in Canada?

Increasingly, yes. Quebec's Law 25 already provides a right to deletion in defined circumstances, and the proposed CPPA introduces a right to disposal of personal information across Canada. You can also withdraw consent under PIPEDA, which often obligates the organisation to stop using and, in many cases, delete your data.

What should I do if a company refuses to give me access to my data?

First, follow up in writing with the company's privacy officer and cite the applicable law (PIPEDA, Law 25, or provincial PIPA). If they still refuse or fail to respond within 30 days, file a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. You may also have grounds to seek damages in court.

Do Canadian privacy laws apply to foreign companies?

Yes, when there is a "real and substantial connection" to Canada — such as offering services to Canadian residents or collecting data from within Canada. The OPC has repeatedly asserted jurisdiction over foreign-based platforms, and Quebec's Law 25 explicitly applies to any organisation processing the personal information of Quebec residents.

How can small businesses in Canada become privacy compliant?

Start by mapping the personal information you collect, drafting a clear privacy policy, designating a privacy officer, implementing basic security controls (encryption, access controls, backups), and establishing a breach response plan. The OPC publishes free tools and guides specifically for small and medium-sized enterprises, and consulting a privacy lawyer for a one-time review is often worth the investment.

Final Thoughts

Privacy rights in Canada in 2026 are stronger, broader, and more actively enforced than ever before. Between PIPEDA, Quebec's Law 25, provincial PIPAs, and the pending reforms under Bill C-27, both individuals and organisations must stay informed to protect themselves and remain compliant. For Canadians, this means more control over personal data and clearer avenues for recourse. For businesses, it means privacy is no longer a compliance afterthought — it is a competitive differentiator and a legal necessity.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles