Rules
What PIPEDA and the Privacy Commissioner mean for Canadian PR data
PIPEDA Privacy Commissioner PR: how Canadian teams handle consent, breach reporting, retention and OPC enforcement when campaign data is at stake.
What to take away
- PIPEDA Privacy Commissioner PR work comes down to ten fair information principles, valid consent, and a real privacy officer.
- Consent must be meaningful, and marketing emails and texts also face CRTC rules under CASL.
- Breach reporting to the Office of the Privacy Commissioner is mandatory when there is a real risk of significant harm.
- The OPC publishes findings that show enforcement is often a slow burn of recommendations, not fines.
- Quebec's Law 25, Alberta's PIPA and BC's PIPA add provincial duties that can bite harder than PIPEDA.
- Data retention and vendor contracts are where most campaign data problems start.
What PIPEDA requires of PR data handling
PIPEDA is Canada's private-sector privacy law. It applies to organizations that collect, use or disclose personal information in the course of commercial activity. A PR agency pitching a client, running a media list or building a campaign audience is doing commercial activity. The law follows the data.
Personal information is broad. A name, email, phone number, IP address, device identifier or a note that someone attended an event all count. Even a journalist contact record in a media database is personal information about that journalist.
The Office of the Privacy Commissioner of Canada oversees PIPEDA for the private sector. It investigates complaints, audits organizations, publishes guidance and can take matters to Federal Court. The OPC's plain-language overview of the law sets out what PIPEDA covers and how it applies to organizations handling personal information.
Ten principles sit at the core. Accountability heads the list. Then come identifying purposes, consent, limiting collection, and limiting use and disclosure. Accuracy, safeguards, openness, individual access and challenging compliance close it out. These are not slogans. They are the test an investigator applies.
Accountability is the one PR teams underestimate. Someone in the organization must be designated as the privacy officer. That person fields access requests, handles complaints and knows where the data lives. A shared inbox is not an accountable person.
Purpose matters too. If you collect an email address to send a media release, you cannot quietly add that person to a consumer newsletter. New purpose means new consent, or a legal basis that fits.
Safeguards cover the boring things: who can export a list, whether laptops are encrypted, whether a freelancer gets access to the full CRM. Most breaches in communications work are not sophisticated attacks. They are emailed spreadsheets and misdirected CC lines.
The full statutory text is worth reading once, at least the sections on consent and disclosure. It is shorter than most people expect. The Personal Information Protection and Electronic Documents Act is the source document for every claim below.
The Privacy Commissioner is not the only regulator in the room. The CRTC enforces Canada's anti-spam law for commercial electronic messages. The Competition Bureau watches misleading advertising. Quebec's Law 25, administered by the Commission d'accès à l'information, imposes its own consent and transparency rules on anyone handling Quebec residents' data.
That mix is why a single national consent checkbox rarely works. A campaign aimed at Ontario, Quebec, British Columbia and Alberta is touching at least four regimes. A public relations messaging framework that assumes one national rule set will not hold up in any of them.
Consent, marketing and the Office of the Privacy Commissioner
Consent under PIPEDA must be meaningful. The individual has to understand what they are agreeing to. Bundled consent buried in a 40-page policy is weak. So is consent obtained by making a service conditional on unrelated data uses.
The law recognizes express and implied consent. Express consent is clearer and safer for marketing. Implied consent can work where the relationship and the context make the person's agreement obvious, such as an existing client expecting relevant updates.
For marketing specifically, the OPC expects consent to be tied to a described purpose. "We may share your information with partners" is not a described purpose. "We will send you our monthly industry briefing" is.
The OPC's guidance for businesses walks through consent, marketing and personal information in practical terms. It is the first place to check before a campaign launches, not after a complaint arrives.
Taking back consent must be just as simple as giving it. If someone opts out of a newsletter but keeps getting event invitations from the same list, the opt-out was cosmetic.
CASL sits on top of PIPEDA. Commercial electronic messages to Canadians need consent and a working unsubscribe mechanism, and the CRTC can pursue violations. A PIPEDA-compliant list can still fail CASL if the unsubscribe link is broken or the sender information is missing.
Quebec's Law 25 raises the bar. It requires privacy policies to be clear and accessible, and it sets rules for transferring personal information outside Quebec. A national campaign that treats Quebec as just another province is exposed.
Indigenous and francophone audiences deserve specific thought. Consent language in English only, or a privacy notice that ignores how a community wants to be contacted, undercuts the consent itself. Language and context are part of validity.
Good consent design is not a legal afterthought. It shapes the form, the landing page and the follow-up sequence. Teams that treat it as a design constraint build cleaner lists and better response rates.
Breach reporting duties and timelines
Breach reporting is mandatory under PIPEDA. An organization must report to the Office of the Privacy Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm.
Significant harm is broad. The list covers bodily harm, humiliation and damage to reputation or relationships. It also covers loss of employment, business or professional opportunities, plus financial loss. Identity theft and negative effects on credit records sit on the same list.
The test is not whether harm happened. It is whether a reasonable person would see a real risk of it. Sensitivity of the data and the probability of misuse both matter. A leaked list of media contacts is not the same as leaked donor payment details.
Timelines are tight. Report to the OPC as soon as feasible after the organization determines a breach occurred. There is no grace period for investigating first and deciding later.
Individuals must also be notified if the breach creates a real risk of significant harm to them. The notice has to be clear enough for them to understand the risk and take steps to reduce it.
Organizations must keep records of every breach of security safeguards involving personal information, whether or not it meets the reporting threshold. Those records must be kept for a set period and provided to the OPC on request.
The OPC's actions and decisions page collects investigation reports, audit findings and breach outcomes. Reading a few is the fastest way to calibrate what the office treats as serious.
Notification to other parties may be required too. If a breach could affect another organization, or if a third party caused it, that party needs to know. Contracts should say who notifies whom and within what window.
Breach response is a communications problem as much as a legal one. Who speaks, what is said, and how quickly are decisions that should be made before an incident, not during one. This is one of the places common marketing communications strategy questions matter most: teams track campaign reach but never time their own incident response.
Enforcement: recent OPC findings and decisions
Enforcement under PIPEDA is not mainly about fines. The OPC investigates complaints, issues findings, makes recommendations and publishes reports. Most organizations comply. Those that do not can face court action.
Recent OPC findings repeatedly turn on consent and accountability. Investigations have found organizations collecting more personal information than needed, keeping it longer than necessary, and failing to explain clearly why it was collected.
A recurring theme is the gap between a privacy policy and actual practice. A policy that promises deletion on request is worthless if no one on the team knows how to delete a record from the CRM.
The OPC also watches how organizations handle access requests. Individuals have a right to know what personal information an organization holds about them and to challenge its accuracy. Slow or evasive responses attract scrutiny.
The office has pushed for stronger accountability in areas like advertising technology and data-driven marketing, where personal information moves through many hands. If your campaign uses audience targeting or tracking pixels, that chain is your responsibility.
The OPC's news and announcements page is where enforcement priorities surface first. Watching it is cheaper than learning about a shift through a complaint.
Provincial regulators matter as much. Quebec's Commission d'accès à l'information enforces Law 25 with its own powers. Alberta and British Columbia have privacy commissioners with their own statutes. A complaint often lands at the provincial door first.
Court outcomes are rare but instructive. When the OPC takes a matter to Federal Court, the facts usually involve repeated refusal to cooperate rather than a single mistake.
The practical read for PR teams: enforcement risk is less about a headline fine and more about a published finding that names your client. Reputation damage from a privacy investigation is a communications outcome.
PIPEDA Privacy Commissioner PR: applying guidance to campaigns
Start with a data map. List every place personal information enters a campaign: landing pages, event registrations, media databases, influencer lists, analytics tools and the CRM. Most teams find two or three they forgot.
For each entry point, write down the purpose in one sentence. If you cannot, the collection is probably not justified. This is the discipline the OPC expects and the one auditors check first.
Build consent into the form, not the footer. A clear checkbox, a plain description of what will be sent, and an easy opt-out. Test it with someone outside the team.
Segment by jurisdiction. Quebec residents need Law 25 treatment. Alberta and BC have their own rules. A single national flow with no regional logic is a design flaw.
Consider language. A francophone audience should see consent language in French. Indigenous communities may have their own expectations about how information is shared and who speaks for the community.
Train the people who touch the list. Account coordinators, interns and freelancers all handle personal information. A one-page guide on what they can and cannot do with it prevents most incidents.
Measurement is part of this. Tracking pixels and third-party analytics collect personal information, and each one needs a purpose and a lawful basis. When you weigh what matters most in corporate communications vendor pitches, ask where the data is stored and how long it is kept.
Before signing with an agency, add privacy to the crisis communications checklist. Ask who their privacy officer is, how they handle a breach, and what happens to your data when the contract ends.
Budget for it. CRTC broadcast PR rules rarely itemize privacy work, which means it either gets done badly or billed as a surprise. Raise it early.
Vendor contracts, lists and data retention
Vendors are the weakest link in most campaign data chains. A media monitoring platform, a CRM, a survey tool and a translation vendor all touch personal information. Each one needs a contract that addresses privacy.
At minimum, the contract should say what data the vendor receives, why, how long it keeps it, who else can see it, and what happens on termination. Vague language about "business purposes" is not enough.
Transfers outside Canada need attention. PIPEDA allows transfers but the transferring organization remains accountable. Quebec's Law 25 adds a requirement to assess whether the destination offers adequate protection.
Data retention is the principle teams ignore longest. Personal information should be kept only as long as needed for the purpose it was collected for. A media list from 2019 is a liability, not an asset.
Set retention periods by data type. Event registrations might be kept for a year. Media contacts might be refreshed annually. Suppression lists, the records of who opted out, should be kept longer so you do not contact them again.
Deletion has to be real. Removing a contact from the active list while leaving them in a backup or an archived spreadsheet is not deletion. Document the process and who performs it.
Access requests need an owner and a routine. If a journalist or customer asks what you hold about them, someone should be able to answer within the statutory timeframe.
| Data type | Typical purpose | Suggested retention |
|---|---|---|
| Media contact records | Pitching and media relations | Refresh annually |
| Event registrations | Logistics and follow-up | 12 months after event |
| Newsletter subscribers | Marketing communications | Until opt-out, then suppression |
| Campaign analytics | Performance measurement | Aggregated, short window |
| Suppression and opt-out lists | Honouring preferences | Indefinite |
A compliance checklist for campaign data
Use this before a campaign goes live. It is not legal advice, but it covers the questions the OPC and provincial regulators ask.
- A named privacy officer is accountable for campaign data.
- Every collection point has a written purpose in one sentence.
- Consent language is clear, unbundled and easy to withdraw.
- Quebec, Alberta and BC residents get treatment that fits their provincial rules.
- Consent and privacy notices are available in French where the audience needs it.
- Vendor contracts cover data use, retention, transfers and breach notice.
- A breach response plan names who reports, who notifies and who speaks.
- Retention periods are set by data type and deletion is verified.
- Access request handling has an owner and a documented routine.
- Staff and freelancers handling lists have been trained this year.
Work through it in order. The first item, accountability, is what makes the rest possible. Without a named owner, every other box gets ticked once and forgotten.
Common questions
Does PIPEDA apply to a small PR agency? Yes, if it collects, uses or discloses personal information in commercial activity. Size does not exempt an organization, though the OPC considers scale when assessing compliance.
Can we email journalists without consent? CASL allows some messages to published business addresses where the message is relevant to the recipient's role. Keep the unsubscribe working and the sender identification accurate.
What counts as a reportable breach? Any breach of security safeguards where there is a real risk of significant harm. Sensitivity of the data and the chance of misuse drive the assessment.
Do we need to tell the OPC about every incident? No, but you must keep a record of every breach involving personal information and provide those records to the OPC on request.
How long can we keep a media list? Only as long as needed for the purpose it was collected for. Refresh contacts annually and delete records that no longer serve a purpose.
What happens if we ignore an OPC recommendation? The OPC can pursue the matter in Federal Court, and the finding is published. The reputational cost usually exceeds the cost of fixing the problem.


