
Guides
What PIPEDA and the Privacy Commissioner mean for Canadian PR data
PIPEDA Privacy Commissioner PR: how Canadian teams handle consent, breach reporting, retention and OPC enforcement when campaign data is at stake.
What to take away
- PIPEDA Privacy Commissioner PR work comes down to ten fair information principles, valid consent, and a real privacy officer.
- Consent must be meaningful, and marketing emails and texts also face CRTC rules under CASL.
- Breach reporting to the Office of the Privacy Commissioner is mandatory when there is a real risk of significant harm.
- The OPC publishes findings that show enforcement is often a slow burn of recommendations, not fines.
- Quebec's Law 25, Alberta's PIPA and BC's PIPA add provincial duties that can bite harder than PIPEDA.
- Data retention and vendor contracts are where most campaign data problems start.
What PIPEDA requires of PR data handling
PIPEDA is Canada's private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of commercial activity. A PR agency pitching a client, running a media list or building a campaign audience is doing commercial activity. The law follows the data.
Personal information is broad. A name, email, phone number, IP address, device identifier or a note that someone attended an event all count. Even a journalist contact record in a media database is personal information about that journalist.
The Office of the Privacy Commissioner of Canada oversees PIPEDA for the private sector. It investigates complaints, audits organizations, publishes guidance and can take matters to Federal Court. The OPC's plain-language overview of the law sets out what PIPEDA covers and how it applies to organizations handling personal information.
Ten principles sit at the core. Accountability heads the list. Then come identifying purposes, consent, limiting collection, and limiting use and disclosure. Accuracy, safeguards, openness, individual access and challenging compliance close it out. These are not slogans. They are the test an investigator applies.
Accountability is the one PR teams underestimate. Someone in the organization must be designated as the privacy officer. That person fields access requests, handles complaints and knows where the data lives. A shared inbox is not an accountable person.
Purpose matters too. If you collect an email address to send a media release, you cannot quietly add that person to a consumer newsletter. New purpose means new consent, or a legal basis that fits.
Safeguards cover the boring things: who can export a list, whether laptops are encrypted, whether a freelancer gets access to the full CRM. Most breaches in communications work are not sophisticated attacks. They are emailed spreadsheets and misdirected CC lines.
The full statutory text is worth reading once, at least the sections on consent and disclosure. It is shorter than most people expect. The Personal Information Protection and Electronic Documents Act is the source document for every claim below.
The Privacy Commissioner is not the only regulator in the room. The CRTC enforces Canada's anti-spam law for commercial electronic messages. The Competition Bureau watches misleading advertising. Quebec's Law 25, administered by the Commission d'accès à l'information, imposes its own consent and transparency rules on anyone handling Quebec residents' data.
That mix is why a single national consent checkbox rarely works. A campaign aimed at Ontario, Quebec, British Columbia and Alberta is touching at least four regimes. A public relations messaging framework that assumes one national rule set will not hold up in any of them.
Consent, marketing and the Office of the Privacy Commissioner
Consent under PIPEDA must be meaningful. The individual has to understand what they are agreeing to. Bundled consent buried in a 40-page policy is weak. So is consent obtained by making a service conditional on unrelated data uses.
The law recognizes express and implied consent. Express consent is clearer and safer for marketing. Implied consent can work where the relationship and the context make the person's agreement obvious, such as an existing client expecting relevant updates.
For marketing specifically, the OPC expects consent to be tied to a described purpose. "We may share your information with partners" is not a described purpose. "We will send you our monthly industry briefing" is.
The OPC's guidance for businesses walks through consent, marketing and personal information in practical terms. It is the first place to check before a campaign launches, not after a complaint arrives.
Taking back consent must be just as simple as giving it. If someone opts out of a newsletter but keeps getting event invitations from the same list, the opt-out was cosmetic.
CASL sits on top of PIPEDA. Commercial electronic messages to Canadians need consent and a working unsubscribe mechanism, and the CRTC can pursue violations. A PIPEDA-compliant list can still fail CASL if the unsubscribe link is broken or the sender information is missing.
Quebec's Law 25 raises the bar. It requires privacy policies to be clear and accessible, and it sets rules for transferring personal information outside Quebec. A national campaign that treats Quebec as just another province is exposed.
Indigenous and francophone audiences deserve specific thought. Consent language in English only, or a privacy notice that ignores how a community wants to be contacted, undercuts the consent itself. Language and context are part of validity.
Breach reporting duties and timelines
Breach reporting is mandatory under PIPEDA. An organization must report to the Office of the Privacy Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm.
Significant harm is broad. The list covers bodily harm, humiliation and damage to reputation or relationships. It also covers loss of employment, business or professional opportunities, plus financial loss. Identity theft and negative effects on credit records sit on the same list.
The test is not whether harm happened. It is whether a reasonable person would see a real risk of it. Sensitivity of the data and the probability of misuse both matter. A leaked list of media contacts is not the same as leaked donor payment details.
Timelines are tight. Report to the OPC as soon as feasible after the organization determines a breach occurred. There is no grace period for investigating first and deciding later. The statute gives no number of days for that report.
Individuals must also be notified if the breach creates a real risk of significant harm to them. The notice has to be clear enough for them to understand the risk and take steps to reduce it.
Organizations must keep records of every breach of security safeguards involving personal information, whether or not it meets the reporting threshold. The Breach of Security Safeguards Regulations, SOR/2018-64, require those records to be kept for 24 months after the day the organization determines the breach occurred. The OPC can ask for them at any point in that window.
The OPC's actions and decisions page collects investigation reports, audit findings and breach outcomes. Reading a few is the fastest way to calibrate what the office treats as serious.
Notification to other parties may be required too. If a breach could affect another organization, or if a third party caused it, that party needs to know. Contracts should say who notifies whom and within what window.
Breach response is a communications problem as much as a legal one. Who speaks, what is said, and how quickly are decisions that should be made before an incident, not during one. This is one of the places common marketing communications strategy questions matter most: teams track campaign reach but never time their own incident response.
Enforcement: OPC findings and decisions
Enforcement under PIPEDA is not mainly about fines. The OPC investigates complaints, issues findings, makes recommendations and publishes reports. Most organizations comply. Those that do not can face court action.
Dated findings make the pattern concrete. The OPC's report of findings on Facebook, published in April 2019 after the Cambridge Analytica matter, found the company collected and used personal information without meaningful consent. Its finding against Clearview AI, published in February 2021, held that the company collected facial images and had no valid consent for the collection.
A joint investigation with provincial regulators, reported in June 2022, found the Tim Hortons app collected granular location data without valid consent. In each case the investigator asked whether the organization could explain why it held the data and how long it kept it.
A recurring theme is the gap between a privacy policy and actual practice. A policy that promises deletion on request is worthless if no one on the team knows how to delete a record from the CRM.
The OPC also watches how organizations handle access requests. Individuals have a right to know what personal information an organization holds about them and to challenge its accuracy. Slow or evasive responses attract scrutiny.
If your campaign uses audience targeting or tracking pixels, that chain is your responsibility.
The OPC's news and announcements page is where enforcement priorities surface first. Watching it is cheaper than learning about a shift through a complaint.
Provincial regulators matter as much. Quebec's Commission d'accès à l'information enforces Law 25 with its own powers. Alberta and British Columbia have privacy commissioners with their own statutes. A complaint often lands at the provincial door first.
Court outcomes are rare but instructive. When the OPC takes a matter to Federal Court, the facts usually involve repeated refusal to cooperate rather than a single mistake.
The practical read for PR teams: enforcement risk is less about a headline fine and more about a published finding that names your client. Reputation damage from a privacy investigation is a communications outcome.
PIPEDA Privacy Commissioner PR: applying guidance to campaigns
Start with a data map. List every place personal information enters a campaign: landing pages, event registrations, media databases, influencer lists, analytics tools and the CRM. Most teams find two or three they forgot.
For each entry point, write down the purpose in one sentence. If you cannot, the collection is probably not justified. This is the discipline the OPC expects and the one auditors check first.
Build consent into the form, not the footer. A clear checkbox, a plain description of what will be sent, and an easy opt-out. Test it with someone outside the team.
Segment by jurisdiction. Quebec residents need Law 25 treatment. Alberta and BC have their own rules. A single national flow with no regional logic is a design flaw.
Consider language. A francophone audience should see consent language in French. Indigenous communities may have their own expectations about how information is shared and who speaks for the community.
Train the people who touch the list. Account coordinators, interns and freelancers all handle personal information. A one-page guide on what they can and cannot do with it prevents most incidents.
Measurement is part of this. Tracking pixels and third-party analytics collect personal information, and each one needs a purpose and a lawful basis. When you weigh what matters most in corporate communications vendor pitches, ask where the data is stored and how long it is kept.
Before signing with an agency, add privacy to the crisis communications checklist. Ask who their privacy officer is, how they handle a breach, and what happens to your data when the contract ends.
Budget for it. CRTC broadcast PR rules rarely itemize privacy work, which means it either gets done badly or billed as a surprise. Raise it early.
Vendor contracts, lists and data retention
Vendors are the weakest link in most campaign data chains. A media monitoring platform, a CRM, a survey tool and a translation vendor all touch personal information. Each one needs a contract that addresses privacy.
At minimum, the contract should say what data the vendor receives, why, how long it keeps it, who else can see it, and what happens on termination. Vague language about "business purposes" is not enough.
Transfers outside Canada need attention. PIPEDA allows transfers but the transferring organization remains accountable. Quebec's Law 25 adds a requirement to assess whether the destination offers adequate protection.
Data retention is the principle teams ignore longest. Personal information should be kept only as long as needed for the purpose it was collected for. A media list from 2019 is a liability, not an asset.
Set retention periods by data type. Event registrations might be kept for a year. Media contacts might be refreshed annually. Suppression lists, the records of who opted out, should be kept longer so you do not contact them again.
Deletion has to be real. Removing a contact from the active list while leaving them in a backup or an archived spreadsheet is not deletion. Document the process and who performs it.
Access requests need an owner and a routine. If a journalist or customer asks what you hold about them, someone should answer within 30 days, the period PIPEDA sets.
| Data type | Typical purpose | Suggested retention |
|---|---|---|
| Media contact records | Pitching and media relations | Refresh annually |
| Event registrations | Logistics and follow-up | 12 months after event |
| Newsletter subscribers | Marketing communications | Until opt-out, then suppression |
| Campaign analytics | Performance measurement | Aggregated, short window |
| Suppression and opt-out lists | Honouring preferences | Indefinite |
A compliance checklist for campaign data
Use this before a campaign goes live. It is not legal advice, but it covers the questions the OPC and provincial regulators ask.
- Name a privacy officer and give that person the authority to answer complaints and access requests.
- Write one sentence of purpose for every point where personal information enters the campaign.
- Check that the consent language describes the messages people will actually receive.
- Confirm the opt-out works on the channel the message was sent on.
- List where the data lives, including backups, freelancer laptops and vendor systems.
- Set a retention period for each data type and book the review date.
- Put privacy terms in every vendor contract, including what happens to the data at termination.
- Confirm the Quebec segment gets Law 25 notices and a clear privacy policy.
- Translate consent language for francophone audiences and follow the community's own expectations about contact.
- Keep a breach log and decide in advance who speaks if something goes wrong.







