PIPEDA compliance card for Canadian PR data handling. What PIPEDA and the Privacy Commissioner mean for Canadian PR data
Image: Privacy Notes

Guides

What PIPEDA and the Privacy Commissioner mean for Canadian PR data

PIPEDA Privacy Commissioner PR: how Canadian teams handle consent, breach reporting, retention and OPC enforcement when campaign data is at stake.

What to take away

  • PIPEDA Privacy Commissioner PR work comes down to ten fair information principles, valid consent, and a real privacy officer.
  • Consent must be meaningful, and marketing emails and texts also face CRTC rules under CASL.
  • Breach reporting to the Office of the Privacy Commissioner is mandatory when there is a real risk of significant harm.
  • The OPC publishes findings that show enforcement is often a slow burn of recommendations, not fines.
  • Quebec's Law 25, Alberta's PIPA and BC's PIPA add provincial duties that can bite harder than PIPEDA.
  • Data retention and vendor contracts are where most campaign data problems start.

What PIPEDA requires of PR data handling

PIPEDA is Canada's private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of commercial activity. A PR agency pitching a client, running a media list or building a campaign audience is doing commercial activity. The law follows the data.

Checklist of PIPEDA's ten fair information principles from accountability to challenging compliance (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
These ten principles are the test an OPC investigator applies to PR data handling. Image: Privacy Notes

Personal information is broad. A name, email, phone number, IP address, device identifier or a note that someone attended an event all count. Even a journalist contact record in a media database is personal information about that journalist.

The Office of the Privacy Commissioner of Canada oversees PIPEDA for the private sector. It investigates complaints, audits organizations, publishes guidance and can take matters to Federal Court. The OPC's plain-language overview of the law sets out what PIPEDA covers and how it applies to organizations handling personal information.

Ten principles sit at the core. Accountability heads the list. Then come identifying purposes, consent, limiting collection, and limiting use and disclosure. Accuracy, safeguards, openness, individual access and challenging compliance close it out. These are not slogans. They are the test an investigator applies.

Accountability is the one PR teams underestimate. Someone in the organization must be designated as the privacy officer. That person fields access requests, handles complaints and knows where the data lives. A shared inbox is not an accountable person.

Purpose matters too. If you collect an email address to send a media release, you cannot quietly add that person to a consumer newsletter. New purpose means new consent, or a legal basis that fits.

Safeguards cover the boring things: who can export a list, whether laptops are encrypted, whether a freelancer gets access to the full CRM. Most breaches in communications work are not sophisticated attacks. They are emailed spreadsheets and misdirected CC lines.

The full statutory text is worth reading once, at least the sections on consent and disclosure. It is shorter than most people expect. The Personal Information Protection and Electronic Documents Act is the source document for every claim below.

The Privacy Commissioner is not the only regulator in the room. The CRTC enforces Canada's anti-spam law for commercial electronic messages. The Competition Bureau watches misleading advertising. Quebec's Law 25, administered by the Commission d'accès à l'information, imposes its own consent and transparency rules on anyone handling Quebec residents' data.

That mix is why a single national consent checkbox rarely works. A campaign aimed at Ontario, Quebec, British Columbia and Alberta is touching at least four regimes. A public relations messaging framework that assumes one national rule set will not hold up in any of them.

Consent, marketing and the Office of the Privacy Commissioner

Consent under PIPEDA must be meaningful. The individual has to understand what they are agreeing to. Bundled consent buried in a 40-page policy is weak. So is consent obtained by making a service conditional on unrelated data uses.

Comparison table of express versus implied consent under PIPEDA for marketing (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Express consent is clearer and safer for marketing; implied consent only works where context makes agreement obvious. Image: Privacy Notes

The law recognizes express and implied consent. Express consent is clearer and safer for marketing. Implied consent can work where the relationship and the context make the person's agreement obvious, such as an existing client expecting relevant updates.

For marketing specifically, the OPC expects consent to be tied to a described purpose. "We may share your information with partners" is not a described purpose. "We will send you our monthly industry briefing" is.

The OPC's guidance for businesses walks through consent, marketing and personal information in practical terms. It is the first place to check before a campaign launches, not after a complaint arrives.

Taking back consent must be just as simple as giving it. If someone opts out of a newsletter but keeps getting event invitations from the same list, the opt-out was cosmetic.

CASL sits on top of PIPEDA. Commercial electronic messages to Canadians need consent and a working unsubscribe mechanism, and the CRTC can pursue violations. A PIPEDA-compliant list can still fail CASL if the unsubscribe link is broken or the sender information is missing.

Quebec's Law 25 raises the bar. It requires privacy policies to be clear and accessible, and it sets rules for transferring personal information outside Quebec. A national campaign that treats Quebec as just another province is exposed.

Indigenous and francophone audiences deserve specific thought. Consent language in English only, or a privacy notice that ignores how a community wants to be contacted, undercuts the consent itself. Language and context are part of validity.

Breach reporting duties and timelines

Breach reporting is mandatory under PIPEDA. An organization must report to the Office of the Privacy Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm.

Timeline of PIPEDA breach reporting steps from breach to record keeping (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Report to the OPC as soon as feasible; there is no grace period for investigating first. Image: Privacy Notes

Significant harm is broad. The list covers bodily harm, humiliation and damage to reputation or relationships. It also covers loss of employment, business or professional opportunities, plus financial loss. Identity theft and negative effects on credit records sit on the same list.

The test is not whether harm happened. It is whether a reasonable person would see a real risk of it. Sensitivity of the data and the probability of misuse both matter. A leaked list of media contacts is not the same as leaked donor payment details.

Timelines are tight. Report to the OPC as soon as feasible after the organization determines a breach occurred. There is no grace period for investigating first and deciding later. The statute gives no number of days for that report.

Individuals must also be notified if the breach creates a real risk of significant harm to them. The notice has to be clear enough for them to understand the risk and take steps to reduce it.

Organizations must keep records of every breach of security safeguards involving personal information, whether or not it meets the reporting threshold. The Breach of Security Safeguards Regulations, SOR/2018-64, require those records to be kept for 24 months after the day the organization determines the breach occurred. The OPC can ask for them at any point in that window.

The OPC's actions and decisions page collects investigation reports, audit findings and breach outcomes. Reading a few is the fastest way to calibrate what the office treats as serious.

Notification to other parties may be required too. If a breach could affect another organization, or if a third party caused it, that party needs to know. Contracts should say who notifies whom and within what window.

Breach response is a communications problem as much as a legal one. Who speaks, what is said, and how quickly are decisions that should be made before an incident, not during one. This is one of the places common marketing communications strategy questions matter most: teams track campaign reach but never time their own incident response.

Enforcement: OPC findings and decisions

Enforcement under PIPEDA is not mainly about fines. The OPC investigates complaints, issues findings, makes recommendations and publishes reports. Most organizations comply. Those that do not can face court action.

Checklist of recurring OPC enforcement themes in recent findings and decisions (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Recent OPC findings repeatedly turn on consent and accountability gaps between policy and practice. Image: Privacy Notes

Dated findings make the pattern concrete. The OPC's report of findings on Facebook, published in April 2019 after the Cambridge Analytica matter, found the company collected and used personal information without meaningful consent. Its finding against Clearview AI, published in February 2021, held that the company collected facial images and had no valid consent for the collection.

A joint investigation with provincial regulators, reported in June 2022, found the Tim Hortons app collected granular location data without valid consent. In each case the investigator asked whether the organization could explain why it held the data and how long it kept it.

A recurring theme is the gap between a privacy policy and actual practice. A policy that promises deletion on request is worthless if no one on the team knows how to delete a record from the CRM.

The OPC also watches how organizations handle access requests. Individuals have a right to know what personal information an organization holds about them and to challenge its accuracy. Slow or evasive responses attract scrutiny.

If your campaign uses audience targeting or tracking pixels, that chain is your responsibility.

The OPC's news and announcements page is where enforcement priorities surface first. Watching it is cheaper than learning about a shift through a complaint.

Provincial regulators matter as much. Quebec's Commission d'accès à l'information enforces Law 25 with its own powers. Alberta and British Columbia have privacy commissioners with their own statutes. A complaint often lands at the provincial door first.

Court outcomes are rare but instructive. When the OPC takes a matter to Federal Court, the facts usually involve repeated refusal to cooperate rather than a single mistake.

The practical read for PR teams: enforcement risk is less about a headline fine and more about a published finding that names your client. Reputation damage from a privacy investigation is a communications outcome.

PIPEDA Privacy Commissioner PR: applying guidance to campaigns

Start with a data map. List every place personal information enters a campaign: landing pages, event registrations, media databases, influencer lists, analytics tools and the CRM. Most teams find two or three they forgot.

Steps for applying PIPEDA guidance to PR campaign data handling (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Start with a data map, then write a one-sentence purpose for each entry point. Image: Privacy Notes

For each entry point, write down the purpose in one sentence. If you cannot, the collection is probably not justified. This is the discipline the OPC expects and the one auditors check first.

Build consent into the form, not the footer. A clear checkbox, a plain description of what will be sent, and an easy opt-out. Test it with someone outside the team.

Segment by jurisdiction. Quebec residents need Law 25 treatment. Alberta and BC have their own rules. A single national flow with no regional logic is a design flaw.

Consider language. A francophone audience should see consent language in French. Indigenous communities may have their own expectations about how information is shared and who speaks for the community.

Train the people who touch the list. Account coordinators, interns and freelancers all handle personal information. A one-page guide on what they can and cannot do with it prevents most incidents.

Measurement is part of this. Tracking pixels and third-party analytics collect personal information, and each one needs a purpose and a lawful basis. When you weigh what matters most in corporate communications vendor pitches, ask where the data is stored and how long it is kept.

Before signing with an agency, add privacy to the crisis communications checklist. Ask who their privacy officer is, how they handle a breach, and what happens to your data when the contract ends.

Budget for it. CRTC broadcast PR rules rarely itemize privacy work, which means it either gets done badly or billed as a surprise. Raise it early.

Vendor contracts, lists and data retention

Vendors are the weakest link in most campaign data chains. A media monitoring platform, a CRM, a survey tool and a translation vendor all touch personal information. Each one needs a contract that addresses privacy.

Checklist of privacy clauses every vendor contract for campaign data needs (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Vague language about business purposes is not enough; each vendor contract needs these terms. Image: Privacy Notes

At minimum, the contract should say what data the vendor receives, why, how long it keeps it, who else can see it, and what happens on termination. Vague language about "business purposes" is not enough.

Transfers outside Canada need attention. PIPEDA allows transfers but the transferring organization remains accountable. Quebec's Law 25 adds a requirement to assess whether the destination offers adequate protection.

Data retention is the principle teams ignore longest. Personal information should be kept only as long as needed for the purpose it was collected for. A media list from 2019 is a liability, not an asset.

Set retention periods by data type. Event registrations might be kept for a year. Media contacts might be refreshed annually. Suppression lists, the records of who opted out, should be kept longer so you do not contact them again.

Deletion has to be real. Removing a contact from the active list while leaving them in a backup or an archived spreadsheet is not deletion. Document the process and who performs it.

Access requests need an owner and a routine. If a journalist or customer asks what you hold about them, someone should answer within 30 days, the period PIPEDA sets.

Data typeTypical purposeSuggested retention
Media contact recordsPitching and media relationsRefresh annually
Event registrationsLogistics and follow-up12 months after event
Newsletter subscribersMarketing communicationsUntil opt-out, then suppression
Campaign analyticsPerformance measurementAggregated, short window
Suppression and opt-out listsHonouring preferencesIndefinite

A compliance checklist for campaign data

Use this before a campaign goes live. It is not legal advice, but it covers the questions the OPC and provincial regulators ask.

Ten-item compliance checklist to run before a PR campaign goes live (What PIPEDA and the Privacy Commissioner mean for Canadian PR data)
Work through the checklist in order; accountability is what makes the rest possible. Image: Privacy Notes
  1. Name a privacy officer and give that person the authority to answer complaints and access requests.
  2. Write one sentence of purpose for every point where personal information enters the campaign.
  3. Check that the consent language describes the messages people will actually receive.
  4. Confirm the opt-out works on the channel the message was sent on.
  5. List where the data lives, including backups, freelancer laptops and vendor systems.
  6. Set a retention period for each data type and book the review date.
  7. Put privacy terms in every vendor contract, including what happens to the data at termination.
  8. Confirm the Quebec segment gets Law 25 notices and a clear privacy policy.
  9. Translate consent language for francophone audiences and follow the community's own expectations about contact.
  10. Keep a breach log and decide in advance who speaks if something goes wrong.

Common questions

Does PIPEDA apply to a small PR agency?
Yes, if it collects, uses or discloses personal information in commercial activity. Size does not exempt an organization, though the OPC considers scale when assessing compliance.
Can we email journalists without consent?
CASL allows some messages to published business addresses where the message is relevant to the recipient's role. Keep the unsubscribe working and the sender identification accurate.
What counts as a reportable breach?
Any breach of security safeguards where there is a real risk of significant harm. Sensitivity of the data and the chance of misuse drive the assessment.
Do we need to tell the OPC about every incident?
No, but you must keep a record of every breach involving personal information and provide those records to the OPC on request.
How long can we keep a media list?
Only as long as needed for the purpose it was collected for. Refresh contacts annually and delete records that no longer serve a purpose.
What happens if we ignore an OPC recommendation?
The OPC can pursue the matter in Federal Court, and the finding is published. The reputational cost usually exceeds the cost of fixing the problem.

More in Guides

Latest from Guides Desk