Key obligations
The obligations that apply to every Canadian business:
- Designate a privacy officer (the person accountable for compliance).
- Publish a clear privacy policy describing what you collect, why, with whom you share it.
- Obtain meaningful consent, especially for sensitive or unexpected uses.
- Limit collection to what is necessary for stated purposes.
- Implement reasonable security safeguards, including encryption at rest and in transit.
- Have a breach response plan with 24/7 contacts and templates.
Province-specific extras
If you operate in:
- BC: BC PIPA applies, including its employee personal information rules; the OIPC BC publishes guidance on them.
- Alberta: Alberta PIPA applies. Breach notification is mandatory and Alberta was the first province to require it.
- Quebec: the private-sector Act as amended by Law 25 applies. A PIA is required for projects involving personal information (s.3.3), and a biometric database must be disclosed to the CAI at least 60 days before it goes into service.
CASL basics
A business that sends commercial electronic messages must:
- Obtain express or implied consent.
- Include sender identification and contact information.
- Provide a working unsubscribe mechanism for 60 days.
- Process unsubscribe requests within 10 business days.
Resources
The OPC publishes a free Privacy Guide for Businesses. Provincial commissioners publish industry-specific guidance.