PIPEDA
The Personal Information Protection and Electronic Documents Act — Canada's federal privacy law governing how private-sector organisations collect, use, and disclose personal information. Structured around ten fair-information principles set out in Schedule 1.
The ten principles
PIPEDA's substantive content is in its ten principles: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. For cloud storage, two matter most: accountability (Principle 1) and safeguards (Principle 7).
Accountability and cloud
Principle 1 makes the organisation that collects personal information accountable for it — even when processing is outsourced. The Office of the Privacy Commissioner's 2009 guidance on cross-border outsourcing (updated 2024) is foundational: organisations remain accountable for personal information under their control even when a third party performs processing. Choosing a foreign-controlled cloud transfers operational responsibility but not legal accountability.
Safeguards and the encryption question
Principle 7 requires "security safeguards appropriate to the sensitivity of the information." The OPC has consistently treated encryption at rest and in transit as the floor for personal information. The harder question — what "appropriate to sensitivity" means when the cloud provider is subject to foreign compelled disclosure — increasingly tilts toward architectures that prevent the provider from accessing plaintext at all.
Provincial overlays
BC PIPA, Alberta PIPA, Quebec Law 25, Ontario PHIPA (health), and Quebec health-information requirements add provincial layers. Quebec's Law 25 in particular requires explicit privacy impact assessments for cross-border transfers — increasing the procurement bar.
How SkyeConnex maps
SkyeConnex's compliance preset packs encode PIPEDA's expectations: encryption posture, Canadian allow-list, retention defaults, audit treatment. The pack itself becomes the documentation of what was applied — auditors read it line-by-line against the framework. Read the full analysis →
Modernisation
Bill C-27 (the Consumer Privacy Protection Act, formerly Bill C-11) is the proposed modernisation of PIPEDA. Final form not yet enacted. Architectures that prevent foreign compelled disclosure will satisfy both PIPEDA and the proposed modernisation.
Related terms
See also
Posts that mention PIPEDA
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readWhat a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read →