Back to Frameworks

Canadian PIPEDA

Canada
4 domains
32 controls

Personal Information Protection and Electronic Documents Act. Federal Canadian private-sector privacy law.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Breach Reporting

5 controls
Controls in the Breach Reporting domain of Canadian PIPEDA5 controls
CodeTitle
s.10.1(1)Breach Notification to Commissioner
s.10.1(3)Breach Notification to Individuals
s.10.1(6)Real Risk of Significant Harm Factors
s.10.2Notification to Third Parties
s.10.3Record Keeping of Breaches

Enforcement

2 controls
Controls in the Enforcement domain of Canadian PIPEDA2 controls
CodeTitle
s.11Consent, Justification and Objection
s.17Documentation

Fair Information Principle

21 controls
Controls in the Fair Information Principle domain of Canadian PIPEDA21 controls
CodeTitle
Principle 4.1Accountability
Principle 4.1.3Accountability for Third Party Transfers
Principle 4.1.4Privacy Management Program
Principle 4.10Challenging Compliance
Principle 4.2Identifying Purposes
Principle 4.2.4New Purpose Requires New Consent
Principle 4.3Consent
Principle 4.3.4Form of Consent
Principle 4.3.8Consent Withdrawal
Principle 4.4Limiting Collection
Principle 4.5Limiting Use, Disclosure, and Retention
Principle 4.5.3Secure Destruction
Principle 4.6Accuracy
Principle 4.7Safeguards
Principle 4.7.3Categories of Safeguards
Principle 4.7.4Employee Awareness
Principle 4.8Openness
Principle 4.8.2Required Openness Information
Principle 4.9Individual Access
Principle 4.9.4Response Timelines
Principle 4.9.5Correction and Notation

Other

4 controls
Controls in the Other domain of Canadian PIPEDA4 controls
CodeTitle
s.5(3)Appropriate Purposes
s.6.1Valid Consent
s.7Certain Legitimate Uses
s.7.3Disclosure for Business Transaction

Frequently Asked Questions

What is Canadian PIPEDA?

Canadian PIPEDA is a compliance framework from Canada with 4 domains and 32 controls. Personal Information Protection and Electronic Documents Act. Federal Canadian private-sector privacy law. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Canadian PIPEDA have?

Canadian PIPEDA has 32 controls organised across 4 domains. The largest domains are Fair Information Principle (21 controls), Breach Reporting (5 controls), Other (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Canadian PIPEDA map to?

Canadian PIPEDA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Canadian PIPEDA compliance?

Start your Canadian PIPEDA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Canadian PIPEDA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required