Skip to main content

Reference

Privacy glossary: 257 terms, explained in plain language.

I put this glossary together because privacy law reads like a foreign language — even for people who work with it every day. These are the 257 terms I find myself explaining most: Law 25, PIPEDA, CASL, the CAI and OPC, consent, PIAs, AI governance, and the individual rights behind them.

Each definition is a plain-language summary to help you get oriented — not legal advice, and not a substitute for reading the statute or talking to qualified counsel about your facts.

Reading someone else's policy or notice? Paste it into the jargon decoder— it uses these same 257 definitions to translate privacy text into plain language, right in your browser.

A

Access request (30-day rule)#

An access request is how you ask an organization what personal information it holds about you. Under PIPEDA and Québec's Law 25, the organization generally has 30 days to respond, either with the information or a refusal with reasons. Missing the deadline is a red flag that privacy regulators take seriously.

Access request exceptions (PIPEDA)#

Access request exceptions are the situations where PIPEDA lets an organization refuse to give a person their information, such as where disclosure would reveal confidential commercial information, compromise an investigation, or identify another individual. Refusals must be explained with reasons, and blanket refusals without examining the request are not allowed. These exceptions are read narrowly, in favor of the requester's right of access.

Access request fees (PIPEDA)#

Under PIPEDA, organizations can charge a reasonable fee for responding to an access request, but they must tell the person the fee in advance and give them the chance to withdraw the request. Many organizations charge nothing to keep the process simple and goodwill intact. A fee that is really a barrier to access will not survive a regulator's review.

Access to Information Act#

The Access to Information Act gives the public a right to request records held by federal institutions, subject to exemptions. Unlike the Privacy Act, it covers records generally rather than just personal information about the requester. Institutions must respond within 30 days, with limited extensions, and refusals can be complained about to the Information Commissioner.

Accountability#

Accountability means the organization is responsible for the personal information it collects, even after handing it to a vendor. PIPEDA makes it a named principle; Law 25 puts the duty squarely on the person carrying on the enterprise. In practice it means named owners, documented decisions, and evidence, not just a policy PDF.

Accuracy principle (PIPEDA)#

The accuracy principle says personal information must be as accurate, complete, and up to date as necessary for the purposes it is used for. A mailing list can tolerate some staleness; a credit decision cannot. Organizations also have to minimize the chance that inaccurate information gets passed on when they disclose it.

Act respecting Access (Quebec public sector)#

This is Quebec's public-sector statute governing access to documents held by public bodies and the protection of personal information within them. It plays the role that FIPPA-type laws play in other provinces. The CAI oversees both halves: access and privacy.

Act respecting the protection of personal information in the private sector (Quebec)#

This is Quebec's private-sector privacy statute, the counterpart to PIPEDA for organizations doing business in the province. Bill 64 modernized it in 2021, introducing rules on automated decisions, incident notification, and default privacy settings. Law 25 is the popular shorthand for the Bill 64 reforms to this act.

Adequacy decision (EU)#

The European Commission can issue an adequacy decision finding that another country's privacy law protects personal data well enough that data can flow there from the EU without extra safeguards. It is the strongest transfer basis under the GDPR and applies to the whole receiving country at once. Canada holds a partial adequacy finding covering commercial organizations under PIPEDA, which is why EU-to-Canada commercial transfers usually need no extra paperwork.

Administrative monetary penalties (CASL)#

Administrative monetary penalties are the CRTC's main enforcement tool under CASL: fines issued without a criminal trial, with maximums among the highest in Canadian regulatory law. They scale with the violation and the organization's history, and directors and officers can be personally liable if they directed or acquiesced. Voluntary compliance undertakings are often negotiated as an alternative.

ADMT#

ADMT stands for automated decision-making technology: systems that make or support decisions about people, like screening résumés, scoring credit, or triaging benefits, with little or no human involvement in each case. Regulators treat it as high-risk because errors and bias scale instantly and affected people often cannot see or challenge the logic. Under Law 25, organizations must inform individuals when a decision about them is made exclusively through automated processing.

Age assurance#

Age assurance is the broader practice of estimating or confirming a user's age, covering everything from self-declaration and document checks to estimation methods that infer an age range without asking for identity. Good age assurance returns only an attribute, like “over 16,” and retains nothing else, so the check cannot become a tracking database. The privacy challenge is matching the strength of the method to the risk: stronger assurance usually means collecting more personal information, which is exactly what data minimization pushes against.

Under Law 25, a child under 14 cannot give valid consent for the collection, use, or disclosure of their personal information, the parent or tutor must consent instead. Organizations dealing with young users need parental-consent flows, not just a ticked box. This raised the bar well above the old norms.

Age verification#

Age verification is the process of confirming that a user meets a minimum age before letting them use a service, for example checking an ID document or running a verified age check at sign-up. Proposals like the EU Kids Act and Canada's Bill C-34 would make it a precondition for social media and other services used by minors. The privacy-safe version proves the age attribute without storing the identity evidence behind it, because a verification log that keeps everyone's documents becomes a high-value target.

Related insight: EU Kids Act age-verification article

Agent of a custodian#

An agent is someone authorized to act for a health information custodian with respect to personal health information: employees, contractors, and sometimes students or volunteers. Agents may only use the information as the custodian permits and must notify the custodian of breaches or privacy complaints. The custodian remains accountable for what its agents do.

AIDA (Canada)#

AIDA is Canada's proposed AI law, introduced as part of Bill C-27. It would require organizations building or using high-impact AI systems to assess and mitigate risks, keep records, and notify authorities of serious harms. Because it is still a proposal, the details are not settled, so treat any claimed obligations from it as subject to change.

Alberta PIPA#

Alberta PIPA is Alberta's private-sector privacy law, covering the collection, use, and disclosure of personal information by organizations in the province. It has been deemed substantially similar to PIPEDA, so it displaces the federal law for most Alberta business activity. Unlike PIPEDA, it gives the provincial commissioner the power to issue binding orders and fines.

Algorithmic impact assessment#

An algorithmic impact assessment is a structured review of what could go wrong with an automated system before it is deployed: who it affects, how it could discriminate, and what safeguards are needed. Several Canadian governments already require versions of it for their own AI tools. Private-sector organizations are adopting the practice to show regulators they took AI risk seriously.

Anonymization criteria (Law 25/CAI)#

Anonymization means altering personal information so it no longer allows identification of the person, and Law 25 reserves the label for irreversible processes. The CAI sets the criteria, focusing on irreversibility and resistance to re-identification through reasonable means. Techniques that can be reversed with outside data are de-identification, not anonymization, and they do not escape the law.

Anonymization vs. de-identification#

De-identification removes direct identifiers (like names) so someone can't be picked out directly, but the data can still count as personal information. Anonymization goes further: it is meant to be irreversible, so the data no longer relates to an identifiable person at all. Law 25 treats the two differently, anonymized information falls outside the Act, while de-identified information does not.

APPI (Japan)#

Japan's APPI is the national law governing how businesses handle personal information. It was substantially amended in 2020 to add stronger individual rights, and Japan holds an EU adequacy decision for commercial transfers. Canadian organizations working with Japanese partners will see APPI-style clauses in those contracts.

Appropriate purposes (PIPEDA section 5(3))#

Appropriate purposes is the PIPEDA rule that an organization may collect, use, or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances. It acts as a backstop, so consent alone does not make a shady practice lawful. Regulators have used it against purposes like covert surveillance and selling location data without a defensible reason.

As soon as feasible (breach reporting timing)#

As soon as feasible is PIPEDA's timing standard for breach notifications to the Commissioner and affected individuals once the real risk threshold is met. It does not set a fixed number of days; instead it expects prompt action given what the organization knew and when. Delays spent on internal deliberation rather than investigation tend to draw regulatory scrutiny.

Audit logs (health)#

Audit logs in health care record who accessed a patient's electronic health information, when, and what they did with it. Custodians must be able to produce them on request, and they are the primary evidence in snooping investigations. Patients can ask for a list of who has viewed their records, and the logs make that answer possible.

B

B2B exemption (CASL)#

The B2B exemption allows commercial electronic messages between organizations when the sender and recipient have a relationship and the message concerns the recipient's activities, roles, or functions. In practice, it means business-to-business outreach to work addresses about work matters can proceed without consent. It does not cover messages to personal addresses or pitches unrelated to the recipient's role.

Background checks (privacy)#

Background checks are pre-employment screens of candidates: criminal records, credit history, references, education verification, and sometimes social media. Privacy law requires consent and limits collection to what is reasonable for the position, so a credit check for a cashier role needs justification. In some provinces, criminal record checks are further restricted by human rights and policing-record laws.

BC FIPPA#

BC's Freedom of Information and Protection of Privacy Act covers provincial public bodies, including ministries, municipalities, and universities. It includes distinctive data-residency expectations that made British Columbia an early outlier on keeping public-sector data in Canada. BC's OIPC enforces it.

BC PIPA#

BC PIPA is British Columbia's private-sector privacy law, governing how organizations in the province handle personal information. Deemed substantially similar to PIPEDA, it replaces the federal law for most private-sector activity in BC. It is known for its strict employee personal information rules and the commissioner's order-making powers.

Bill 64 (Quebec)#

Bill 64 is the statute that modernized Quebec's private-sector privacy law. Passed in 2021, it substantially amended the Act respecting the protection of personal information in the private sector, with the resulting package of reforms usually known as Law 25. Think of Law 25 as the nickname and Bill 64 as the law that delivered it.

Binding corporate rules (BCRs)#

Binding corporate rules are an internal privacy code that a multinational group writes and gets approved by European regulators, so it can move personal data between its own companies worldwide. They are legally binding on every member company and must be enforceable by the individuals whose data is transferred. Smaller companies rarely use them because the approval process is long and expensive.

Biometric database declaration (Law 25)#

Before creating a database of biometric characteristics, such as fingerprints, facial images, or voiceprints, an organization must file a declaration with the CAI. The filing describes the database and its purposes, and any later change to those purposes must also be declared. Biometrics are treated as especially sensitive, so this extra layer of transparency is built into the law.

Biometric information#

Biometric information identifies you through unique physical traits: fingerprints, face geometry, voiceprints, iris scans. Because it can't be changed if compromised, Québec law treats it as sensitive and requires organizations to disclose biometric databases to the CAI before creating them. Collect it only when truly necessary.

Breach / confidentiality incident#

A confidentiality incident is Québec's term for a privacy breach: unauthorized access, use, communication, or loss of personal information. Law 25 requires organizations to keep a register of every incident and to notify the CAI and affected individuals when there is a risk of serious injury. PIPEDA has a parallel breach-notification duty to the OPC and individuals when there is a real risk of significant harm.

Breach notification content (PIPEDA)#

When PIPEDA requires breach notification, the notice to affected individuals must contain prescribed content: a description of the breach, the kinds of information involved, steps the organization is taking, and what the individual can do to reduce the risk. Notices to the Commissioner go through a prescribed form with similar detail. Vague reassurance without these elements does not satisfy the law.

Breach record-keeping (PIPEDA)#

Breach record-keeping is the PIPEDA requirement that organizations record every breach of security safeguards involving personal information, whether or not it meets the notification threshold. The records must be kept for a prescribed period and made available to the Commissioner on request. Regulators use these records to check whether an organization's notification decisions were reasonable.

Business contact information#

Business contact information is details like a person's work title, work address, and work phone number or email that identify them in their professional role. PIPEDA does not treat it as personal information when it is collected, used, or disclosed solely to communicate about employment or business. This is why sending a work email to a colleague's office address does not trigger the usual consent rules.

BYOD (bring your own device)#

BYOD, bring your own device, is the workplace practice of employees using personal phones or laptops for work. It creates a privacy collision: the employer's need to secure work data versus the employee's personal information on the same device. Good programs use technical separation like work profiles, written policies, and clear rules about remote wipe, rather than blanket access to the personal device.

C

CAI (Commission d'accès à l'information)#

The Commission d'accès à l'information du Québec is the province's privacy and access-to-information regulator, covering both public bodies and private enterprises. Under Law 25 it gained real teeth: investigation powers, orders, and the ability to impose administrative monetary penalties. It is the first place Québecers turn with a complaint.

CAI authorization (research)#

Before an organization can receive personal information for research without consent, it must obtain the CAI's authorization. The application sets out the project's purpose, the information needed, and how it will be protected. This keeps a regulator in the loop on high-risk secondary uses instead of leaving it to the parties' judgment alone.

CAI investigation powers#

The CAI can investigate on its own initiative or after a complaint, and it can demand documents, access systems, and question people under oath. Organizations that refuse to cooperate risk separate penal offences. These powers are the enforcement engine behind Law 25's rules.

CAI mediation#

The CAI can offer mediation to resolve disputes between individuals and organizations over access requests or correction requests. It is an informal, consensual process aimed at settling the matter without a full examination or order. Many complaints that start out confrontational end here, which saves time for both sides.

Capacity to consent in health privacy means the individual can understand the information relevant to the decision and appreciate its reasonably foreseeable consequences. Under PHIPA, capacity is presumed and assessed relative to the specific decision, not as a blanket label. When a person lacks capacity, a substitute decision-maker steps in following a ranked list.

CASL private right of action (suspended)#

CASL originally included a private right of action letting individuals sue senders directly for violations. It has been suspended by government order since before it was due to take effect, so no private lawsuits can proceed under it. For now, enforcement runs only through the CRTC, the Competition Bureau, and the Privacy Commissioner.

CCPA (California)#

The CCPA is California's main consumer privacy law, in force since 2020. It gives Californians rights to know, delete, and opt out of the sale of their personal information, and it applies to businesses over certain size thresholds even if they are not based in California. Canadian companies that sell into the US market often have to comply with it alongside Canadian law.

Centralized health record (Quebec)#

Quebec's centralized health record makes clinical information available across providers through a shared provincial record system. Clinicians can access a patient's history regardless of where care was delivered, subject to consent and access controls. Patients can also see their own information and, in defined circumstances, restrict who views it.

Challenging compliance (PIPEDA Principle 10)#

Challenging compliance is the tenth PIPEDA principle: anyone can question how an organization follows the law and must get a clear path to do so. Organizations have to designate someone to handle complaints and explain their privacy practices on request. It turns privacy rights from theory into something a person can actually exercise.

Circle of care#

The circle of care is not a legal term but a widely used shorthand for the health providers involved in a person's care who may share personal health information with each other under PHIPA's implied consent. It covers the treating team, not the whole health system: a specialist you were referred to is in, a researcher you never met is out. Patients can still withdraw or withhold consent through a lockbox instruction.

Commercial activity (PIPEDA scope)#

PIPEDA applies to the collection, use, or disclosure of personal information in the course of commercial activity, which means activity with a business or profit-seeking character. Courts have read this broadly, so even a not-for-profit can fall under PIPEDA when it sells things or charges fees. The scope question is why most Canadian private-sector businesses need to comply with the law.

Commercial electronic message (CEM)#

A commercial electronic message is any electronic message that encourages participation in commercial activity: sales emails, texts, direct messages, and even some app notifications. CASL regulates them heavily: you generally need consent before sending, plus proper sender identification and a working unsubscribe. The law's definition is broader than most people expect, which is why marketing teams keep getting it wrong.

Commercial transaction exemption (Law 25)#

When one business acquires or merges with another, personal information needed for the deal can be shared without consent. Both parties must first agree in writing to use it only for that purpose, protect its confidentiality, and limit access. If the transaction falls through, the information must be destroyed or returned.

Complaint to the CAI#

If a Québec organization refuses your access request or you believe it mishandled your information, you can file a complaint with the CAI. The Commission can investigate, mediate, and order an organization to take specific steps. It can now also impose financial penalties for non-compliance.

Computer program installation (CASL)#

CASL's computer program provisions make it unlawful to install software on someone else's computer without consent in the course of commercial activity. Express consent is needed when the installation does things a reasonable user would find unexpected, like collecting personal information or changing settings. The classic targets were spyware and adware bundles, but the rules also catch deceptive browser extensions and bundled installers.

Confidentiality incident register#

Law 25 requires every enterprise to maintain a written register of confidentiality incidents, not just the ones it reports. The register records what happened, when it was discovered, and what was done about it. The CAI can demand a copy at any time, so this is where breach readiness gets audited.

Consent is the permission an individual gives an organization to collect, use, or disclose their information. Implied consent is inferred from actions (like handing over an email at checkout), while express consent is a clear yes, and Law 25 requires express consent for sensitive information. Law 25 also demands that consent be manifest, free, informed, given for specific purposes, and requested separately from other communications when in writing.

Individuals can withdraw consent they previously gave, subject to legal or contractual restrictions. The withdrawal works going forward, data already lawfully used can't be un-rung, but the organization must stop the consented processing. This is why consent management has to be more than a one-time banner click.

Consistent use (Privacy Act)#

Consistent use is a Privacy Act rule that lets a federal institution use personal information for the purpose it was collected for, or for a use consistent with that purpose that the individual would reasonably expect. Uses outside that scope generally need the person's consent or specific legal authority. It is the federal equivalent of purpose limitation in the private sector.

Conspicuous publication is when an email address is posted publicly, for example on a company contact page, without any statement that the person does not want commercial messages. CASL treats that as implied consent, but only for messages relevant to the person's role or business. It does not cover addresses harvested at random or messages unrelated to the published role.

Consumer Privacy Protection Act (proposed federal reform)#

The Consumer Privacy Protection Act is a proposed federal law that would replace PIPEDA's private-sector provisions with a modernized privacy regime. It would give the Commissioner order-making powers and introduce significant administrative penalties, among other changes. Privacy programs track it because it would reshape compliance expectations if enacted.

Contextual integrity#

Contextual integrity is a theory of privacy that says information flows are fine only when they fit the norms of their context: your doctor sharing test results with a specialist is expected, your doctor selling them to a marketer is not. It judges privacy by whether a flow breaks social expectations, not by whether data was technically public. Privacy scholars use it to explain why people object to some data uses even when they agreed to others.

Convention 108+#

Convention 108+ is the Council of Europe's modernized data protection treaty, open to countries outside Europe as well. It sets baseline standards for fair processing, security, and individual rights that its member states must write into national law. Canada has not joined it, but it is the main treaty shaping how other democracies benchmark their privacy regimes.

Cookies, pixels, and SDKs that collect personal information are subject to Law 25's consent rules. Organizations must explain tracking technologies that identify, locate, or profile people and give them a way to deactivate profiling functions. Non-essential trackers generally need an informed opt-in, and privacy settings must default to the highest level of confidentiality.

COPPA (US)#

COPPA is the US federal law protecting the personal information of children under 13 online. Websites and apps aimed at kids, or ones that knowingly collect children's data, must get verifiable parental consent before collecting it. It has been the template for stronger children's privacy rules debated in several countries, including Canada.

CPRA (California)#

The CPRA is the 2020 ballot measure that amended and expanded the CCPA. It created a dedicated enforcement agency, added a right to correct inaccurate data, and introduced limits on sensitive personal information like precise geolocation. It took effect in January 2023 and remains the US law most similar in reach to Canadian privacy statutes.

Critical incident#

A critical incident is an AI safety event serious enough to trigger mandatory reporting. Examples include a model materially enabling harm or behaving far outside its safety evaluations. California's SB 53 uses the concept to decide which events frontier-model developers must disclose to the state. Exact legal thresholds vary by jurisdiction, so map reporting duties per market rather than assuming one global standard.

Cross-border transfer#

A cross-border transfer is any communication of personal information outside Québec (or outside Canada), including cloud storage hosted in another country. Law 25 requires a privacy assessment before the transfer and a written contract ensuring comparable protection at the receiving end. Under PIPEDA, organizations remain accountable and must use contractual safeguards for transfers for processing.

Cross-border transfer PIA (Law 25)#

Before sending personal information outside Quebec, an organization must assess what could happen if the data is accessed or disclosed abroad. The review considers the foreign jurisdiction's legal framework, its privacy protections, and any other factors affecting confidentiality. This is the closest Quebec gets to adequacy decisions: the duty to assess sits with the exporting organization, not the regulator.

CRTC enforcement (CASL)#

The CRTC enforces CASL's rules on commercial electronic messages, unsolicited telecoms, and malware. It investigates complaints, can demand production of records, and issues penalties and undertakings to violators. It coordinates with the Competition Bureau and the Privacy Commissioner, who cover deceptive marketing and the computer program provisions respectively.

CSA Model Code for the Protection of Personal Information#

The CSA Model Code is the 1996 Canadian Standards Association standard that set out ten fair information principles for handling personal data. PIPEDA's Schedule 1 is built directly on it, turning those principles into law. Privacy professionals still cite the Model Code as the original architecture behind Canada's consent-based approach.

D

Dark patterns#

Dark patterns are interface designs that manipulate users into choices they would not otherwise make: pre-ticked boxes, hidden decline buttons, or countdown timers that reset. Regulators increasingly treat them as invalidating consent, because consent obtained through deception is not meaningful. Several Canadian enforcement actions have targeted them.

Data broker#

A data broker is a company that collects personal information about people, mostly from other sources rather than directly, and sells it to advertisers, insurers, employers, and others. Most people have never heard of the brokers trading their profiles. Quebec's Law 25 and US state laws have begun giving individuals rights to find and delete broker-held data.

Data minimization#

Data minimization means collecting only the personal information you actually need for the purpose at hand, nothing more. Both PIPEDA and Law 25 require necessity-based collection. It is the simplest, most underused way to cut privacy risk: data you never collect can't be breached.

Data portability#

Data portability is the right to receive your personal information in a structured, commonly used format and have it transmitted to another organization. Law 25 introduced it in Québec effective September 2024, going beyond what PIPEDA currently offers. It matters most when switching providers, think health apps, banks, and platforms.

Data processing agreement (DPA)#

A data processing agreement is the contract between an organization and a vendor that processes personal information on its behalf. It spells out the permitted purposes, security safeguards, sub-processor rules, breach notification duties, and what happens to the data when the contract ends. A DPA is where accountability gets written down in enforceable terms.

De-indexation / right to be forgotten#

De-indexation is the right to have a link to your personal information removed from search results or to stop its dissemination. Law 25 (in force September 2024) lets individuals ask organizations to cease disseminating their information or de-index hyperlinks attached to their name. It is Québec's version of the broader “right to be forgotten” debate, and the OPC has also issued draft guidance on de-indexing for search engines.

Deemed refusal (access request)#

A deemed refusal happens when an organization fails to respond to an access request within the statutory timeframe, and the law treats the silence as a refusal. The requester can then complain to the regulator as if they had been formally refused. It stops organizations from killing requests by simply ignoring them.

Default privacy settings (Law 25)#

Law 25 requires that the highest level of privacy protection be the default when an organization launches a technological product or service. Users can choose to lower their settings, but they should never have to opt out of invasive defaults. This flips the old model, where products often collected everything unless the user dug through menus to turn it off.

Designated investigative body (PIPEDA)#

A designated investigative body is an organization, such as a fraud or counterfeit watchdog, formally recognized in federal regulations under PIPEDA. It can collect personal information without consent in the course of investigating breaches of agreements or the law, within defined limits. Banks and payment companies rely on this provision when sharing fraud intelligence.

Disclosure (communication of personal information)#

Under Québec's Law 25, the statute's term is “communication”: sharing personal information with anyone outside the enterprise or the original purpose. Communication generally requires consent unless a specific exception applies (such as a legal obligation). PIPEDA uses “disclosure” for the same idea, and cross-border communications trigger extra assessment and contract requirements.

DPDPA (India)#

India's DPDPA is the country's first comprehensive privacy law, passed in 2023. It gives Indians rights over their digital personal data and puts duties on the companies handling it, with significant penalties for breaches. Details are still being filled in through government rules, so Canadian firms doing business in India should watch how it is implemented.

DPIA vs. PIA naming#

DPIA (data protection impact assessment) is the GDPR's name for the assessment; PIA (privacy impact assessment) is the Canadian term used by the OPC and Québec's EIVP (évaluation d'impact sur la vie privée). They are the same family of exercise: identify privacy risks before launching something new. Name aside, Law 25 makes the assessment mandatory for certain projects.

E

Electronic health record (EHR)#

An electronic health record is the province-wide system that pulls together a patient's health information from many providers into one accessible record. PHIPA gives the Minister or a designated agency authority to operate it, with patients able to place lockbox restrictions on who sees what. Access is logged and audited, and snooping by curious staff is a classic enforcement case.

Electronic monitoring policy (Ontario)#

Ontario employers with 25 or more employees must have a written electronic monitoring policy describing whether and how they monitor workers electronically. The Employment Standards Act requires the policy to state if monitoring occurs, but it does not restrict what monitoring is allowed. It is a transparency rule, not a consent rule, and privacy laws still apply on top.

The emergency exception lets an organization collect, use, or disclose personal information without consent where there is an emergency that threatens someone's life, health, or security. A hospital sharing a patient's details with first responders is the classic example. Once the emergency passes, the usual consent rules apply again.

Employee monitoring#

Employee monitoring is the tracking of workers' activity by employers: keystroke logging, email and chat review, location tracking, screen capture, and similar tools. In Canada's private sector, PIPEDA and provincial laws require notice and a reasonable purpose, with consent generally implied from the employment relationship only where expectations are clear. Monitoring that goes beyond what a reasonable person would expect, especially in unionized workplaces, gets struck down.

Employee personal information#

Employee personal information is data about staff, resumes, payroll, performance, health accommodations, monitoring logs. Unlike some other provinces' laws, Law 25 applies fully to employee data, so the same consent, transparency, and access rules apply. Monitoring employees (cameras, keystroke logging, location tracking) needs necessity, proportionality, and clear notice.

Employee personal information (Alberta/BC PIPA)#

Under the Alberta and BC private-sector privacy laws, employee personal information gets its own regime distinct from customer data. Employers can collect, use, and disclose it without consent where it is reasonable for establishing, managing, or terminating employment, with notice to the employee. Customer-style consent rules still apply where the information falls outside that employment relationship purpose.

Employee personal information (Quebec)#

Quebec treats employee personal information as personal information, with no broad employer exemption of the kind some other provinces have. Employers must therefore inform staff, limit collection to what is necessary, and apply consent and security rules to HR data. Employment files are privacy-regulated files.

Encryption#

Encryption scrambles data with a mathematical key so that only someone holding the key can read it. It protects data in transit across networks and data at rest on disks and backups. Canadian regulators treat proper encryption as a basic expectation, and its presence can reduce the harm assessment of a lost device.

End-of-purpose rule (Law 25)#

Once the original purpose for collecting personal information is fulfilled, the organization must either destroy the information or anonymize it according to CAI criteria. There is no legal parking lot for data that might be useful someday. This rule makes purpose limitation operational rather than aspirational.

Equivalent protection (contracts)#

Equivalent protection is the standard that privacy contracts must meet: a vendor or processor must protect personal information to a level comparable to what the originating organization owes. It is typically implemented through contractual clauses covering purpose limits, safeguards, sub-processors, breach notice, and return or deletion at the end. Without equivalent protection in writing, the transfer itself can be a compliance failure.

EU AI Act risk-based approach#

The EU AI Act regulates artificial intelligence according to risk: unacceptable uses are banned, high-risk uses face strict duties, limited-risk uses face transparency duties, and minimal-risk uses face almost nothing. It is the first comprehensive AI statute anywhere, and it applies to providers outside the EU whose systems are used inside it. Canadian AI vendors selling into Europe must figure out where their systems land in this ladder.

EU-US Data Privacy Framework#

The EU-US Data Privacy Framework is the 2023 successor to Privacy Shield: a deal under which the EU found the United States protects data adequately, but only for US companies that self-certify into the program. A certified US vendor can therefore receive EU personal data without extra transfer contracts. Canadian companies should still verify a vendor's certification is current before relying on it.

Exemptions vs exclusions (ATI)#

Under the Access to Information Act, exemptions are discretionary or mandatory reasons to withhold records, such as personal information, solicitor-client privilege, or national security. Exclusions remove records from the Act entirely, so they cannot be requested at all, covering items like published material and Cabinet confidences. The distinction matters because excluded records get no independent review.

Existing business relationship (CASL)#

An existing business relationship means the recipient bought, leased, or contracted for products or services from the sender within the past two years, or made an inquiry or application within the past six months. It is the most common basis for implied consent under CASL. Organizations must track when the window closes, because messages sent on stale implied consent are unlawful.

Existing non-business relationship (CASL)#

An existing non-business relationship covers interactions outside commerce: donations to a charity, membership in a club or association, or volunteer work within the past two years. CASL gives these relationships the same implied-consent treatment as business ones. Political parties and candidates rely on this, alongside a separate exemption for their own messaging.

Explainability (AI)#

Explainability is the ability of an AI system to give a human-understandable account of why it produced a particular output. It matters for privacy and fairness because people cannot challenge decisions they cannot understand, like a rejected application scored by a model. Complete explainability is often technically hard, so the practical question is whether the explanation is good enough for the decision at stake.

Express consent is explicit permission from a recipient to receive commercial electronic messages, given orally, in writing, or by clicking a box. Under CASL the request must name the sender, describe the purpose, and state that consent can be withdrawn, and pre-checked boxes do not count. It has no expiry date: it lasts until the person opts out.

F

Factors in real risk of significant harm#

PIPEDA sets out factors for judging whether a breach creates a real risk of significant harm: the sensitivity of the information, the probability it has been or will be misused, and any other relevant circumstances. Highly sensitive data points toward risk, as does evidence the information is in the wrong hands. Organizations must weigh these factors and document the call, since regulators will second-guess it.

Family and personal relationship exemption (CASL)#

CASL exempts commercial electronic messages sent between people with a family or personal relationship. A personal relationship means prior in-person or voice contact within the past two years plus two-way communication beyond a business interaction. It is meant for genuine personal ties, not for sales reps who once called a prospect.

Federal Court damages (PIPEDA)#

Federal Court damages are the remedy available under PIPEDA when a person applies to the Federal Court after the Commissioner issues a report of findings. The court can order the organization to correct its practices and award damages to the individual, including for humiliation. It is one of the few ways PIPEDA puts money behind a privacy right.

Federal Court judicial review (PIPEDA)#

After the Commissioner issues a report of findings, either the complainant or the Commissioner can apply to the Federal Court for a hearing on the matter. The court hears the case fresh and can order the organization to correct its practices and award damages to the individual. It is the enforcement backstop that gives OPC investigations their ultimate leverage.

Federal Court remedy (Privacy Act)#

When a federal institution refuses a Privacy Act access request, the requester can apply to the Federal Court for review within the statutory time limit. The Court can order disclosure, and the Privacy Commissioner's findings, while not binding, carry weight. It is the one enforcement path with real teeth under the Privacy Act.

Federal works, undertakings and businesses (FWUB)#

Federal works, undertakings and businesses are the federally regulated organizations, like banks, telecoms, airlines, and interprovincial transport companies, where PIPEDA always applies regardless of province. Employees of FWUBs are also covered by PIPEDA for their employee personal information. In Alberta, British Columbia, and Québec, other private-sector organizations fall under their own provincial laws instead.

FIPPA (Ontario)#

FIPPA is Ontario's Freedom of Information and Protection of Privacy Act, covering provincial ministries, agencies, and broader public-sector bodies. It gives individuals access to records held by these bodies and sets rules for how they collect and use personal information. Ontario's Information and Privacy Commissioner oversees it.

FIPPs (US Fair Information Practice Principles)#

The Fair Information Practice Principles are the US-origin set of eight principles for handling personal data: collection limitation, data quality, purpose specification, use limitation, security, openness, individual participation, and accountability. First published by a US advisory committee in 1973, they became the conceptual ancestor of privacy laws worldwide, including Canada's.

The form of consent under PIPEDA ranges from express to implied, depending on how sensitive the information is and how the person would reasonably expect it to be used. Sensitive information, like health or financial details, generally calls for clear express consent. Implied consent may be acceptable for low-sensitivity information used in an obvious way the person would anticipate.

Foundation model#

A foundation model is a large general-purpose AI model, like the big language models, trained on broad data and adapted later for specific tasks. One model can power thousands of applications, which concentrates risk: a flaw or bias in the base model flows into everything built on it. Regulators in the EU and Canada have singled these models out for extra scrutiny.

FPT#

FPT stands for federal-provincial-territorial: joint action by Canada's federal, provincial, and territorial governments. In privacy, it usually means the information and privacy commissioners meeting or acting together, as they did in Ottawa in September 2026 on AI governance. When the FPT commissioners align, organizations operating across provinces get one clear signal instead of thirteen.

Fraud prevention exception (PIPEDA)#

The fraud prevention exception lets organizations collect, use, or disclose personal information without consent to detect, suppress, or prevent fraud. It covers sharing intelligence about suspected fraudsters, including with designated investigative bodies and other organizations. This is why banks can exchange fraud signals without asking the fraudster's permission first.

Fraud prevention use (Law 25)#

An organization may use personal information without consent when doing so is necessary to prevent or detect fraud, or to identify its perpetrators. This is limited to what is genuinely needed for the fraud-fighting purpose. It does not license general surveillance, and the organization must still be able to explain its reasoning.

Frontier model#

A frontier model is a large AI model at or near the cutting edge of capability, meaning the biggest general-purpose models from the leading labs. Regulators single them out because their scale creates novel safety risks that smaller models do not. California's SB 53 requires their developers to publish safety frameworks and report critical safety incidents to the state.

Function creep#

Function creep is when data collected for one purpose gradually gets used for others it was never meant for: a contact-tracing app repurposed for policing, or employee wellness data used in performance reviews. Privacy law fights it with purpose limitation, the rule that personal information may only be used for the purposes it was collected for. Each new use needs its own justification.

G

Genetic Non-Discrimination Act (federal)#

This federal law bans anyone providing goods or services, or entering into or continuing a contract, from requiring a genetic test or asking for its results. It targets discrimination based on genetic characteristics, most famously in insurance and employment. Violations carry criminal penalties, which is rare in Canadian privacy-adjacent law.

Getting Accountability Right (OPC guidance)#

Getting Accountability Right is an OPC, Alberta, and BC guidance document that explains what regulators expect from a privacy management program. It lays out the building blocks: organizational commitment, program controls, and ongoing assessment. Organizations use it as a checklist when standing up or auditing their privacy functions.

Global CBPR system#

The Global CBPR system is a certification scheme run by APEC economies (and now some non-APEC ones) that lets companies demonstrate their privacy practices meet common cross-border standards. Certified companies can move personal data between participating economies with less friction. Canada is a participant, so it shows up in transfer discussions with Asia-Pacific partners.

Global Privacy Control (GPC)#

Global Privacy Control is a browser-level signal that tells websites the user wants to opt out of the sale or sharing of their personal information. Some US state laws require websites to honor it as a valid opt-out. It is the modern successor to the old Do Not Track idea, this time with legal teeth behind it.

Governance framework (Law 25)#

Law 25 requires enterprises to establish and implement governance policies for personal information: roles and responsibilities, a retention schedule, a process for handling complaints, and security measures. The privacy officer oversees this framework, and the policies must be published. It is the documentary spine of Law 25 compliance.

H

Health breach notification (Ontario)#

Ontario's health privacy law requires custodians to notify affected individuals of a privacy breach at the first reasonable opportunity. Serious breaches, including theft, loss, or unauthorized use or disclosure, must also be reported to the Information and Privacy Commissioner. The Commissioner can impose administrative penalties on custodians and their agents for violations.

Health information custodian#

A health information custodian is the person or organization with custody or control of personal health information under Ontario's PHIPA: hospitals, physicians, pharmacies, long-term care homes, and similar providers. Custodians are legally responsible for the information even when agents handle it. They must have information practices, a contact person, and safeguards in place.

Health number (unique identifier)#

The health number is the unique identifier on an Ontario health card, used to identify patients across the health system. PHIPA restricts its collection and use: only custodians and authorized persons may collect it, and only for health purposes. Using health numbers for unrelated purposes, like loyalty programs, is prohibited.

Health research ethics board#

A health research ethics board reviews research proposals that use personal health information to ensure they meet ethical and legal standards. Under PHIPA, its approval is required before a custodian may disclose information to a researcher without consent. The board must weigh the public interest in the research against privacy risks and impose conditions on safeguards.

HIA (Alberta)#

Alberta's Health Information Act governs health information held by custodians such as Alberta Health Services, physicians, and pharmacies. It balances patient privacy with the needs of a functioning health system, allowing defined flows of information for care while restricting the rest. Alberta's OIPC oversees it.

High-impact AI system (AIDA)#

A high-impact AI system is the category of AI that Canada's proposed AIDA would regulate most strictly, covering systems whose use could cause significant harm like biased hiring or unsafe medical advice. Which systems qualify would be defined in regulations that do not yet exist. The label matters because it would trigger assessment, monitoring, and notification duties.

HIPA (Saskatchewan)#

Saskatchewan's Health Information Protection Act governs personal health information held by trustees such as health districts, physicians, and pharmacies. Individuals can access their records and request corrections, and trustees must limit collection and safeguard what they hold. The province's Information and Privacy Commissioner oversees it.

HIPAA (US)#

HIPAA is the US federal law governing the privacy and security of health information held by providers, plans, and their vendors. It sets strict rules on how patient data can be used and shared, and it requires security safeguards plus breach notification. Canadian health organizations deal with its equivalent concepts under provincial health privacy laws like Ontario's PHIPA.

Human in the loop#

Human in the loop means a person reviews and approves an AI system's output before it takes effect, rather than the system acting alone. It is the main safeguard organizations point to when an automated process affects people's rights. The protection is only real if the human can genuinely disagree with the machine, not just rubber-stamp it.

I

ICCPR Article 17#

Article 17 of the International Covenant on Civil and Political Rights turns the UDHR's privacy principle into binding treaty law: everyone has the right to protection against unlawful or arbitrary interference with privacy. Canada ratified the treaty, so this article is part of the international obligations Canadian courts may consider. It is cited in debates on government surveillance and data retention.

Identifiable individual / identifiability#

Information is “personal” when it relates to an identifiable individual, someone who can be picked out directly (name, ID number) or indirectly (a combination of data points). Courts and regulators increasingly accept indirect identifiability. If there's a reasonable possibility of re-identification, treat it as personal information.

Identifying purposes (PIPEDA Principle 2)#

Identifying purposes is the second PIPEDA principle: tell people why you collect their information at or before the time you collect it. People can only consent meaningfully if they know the purpose first. New uses that were not identified up front need fresh notice and consent.

Implied consent lets an organization send commercial electronic messages without explicit permission in narrow situations set out by CASL: an existing business or non-business relationship, or a conspicuously published address without an opt-out notice. It is time-limited, generally two years for business relationships and six months for inquiries, and it lapses if the relationship ends. It never applies where the law requires express consent.

Incident notification content (Law 25)#

When a confidentiality incident creates a serious risk of harm, the organization must notify the CAI and the affected individuals promptly. The notification must describe the incident, the information involved, what the organization is doing about it, and a contact point for questions. It is a communication duty, not an admission of fault, and regulators expect it to be written for real people rather than lawyers.

Incident reporting (AI)#

AI incident reporting is the practice, increasingly a legal duty, of notifying regulators when an AI system causes or nearly causes serious harm. California's SB 53 requires frontier-model developers to report critical incidents to the state, making it the first major jurisdiction with mandatory AI incident reporting. Privacy teams should treat it like breach notification: know your thresholds, have a playbook, and document like a stranger will audit you.

Incident response plan#

An incident response plan is a written playbook for what to do when a security breach hits: who is called, what gets contained first, how evidence is preserved, and when regulators and individuals must be notified. Canadian privacy law sets tight breach-notification timelines, so the plan has to include them. An untested plan fails, which is why organizations rehearse it.

Individual access (PIPEDA Principle 9)#

Individual access is the ninth PIPEDA principle: on request, an organization must tell a person whether it holds their information and let them see it. The person can also challenge the accuracy and completeness of the information and ask for corrections. Organizations generally have 30 days to respond, in an understandable form and at minimal or no cost.

Individual rights#

Individual rights are the powers privacy law gives people over their own information: access, rectification, erasure, de-indexation, portability, and withdrawing consent. Law 25 expanded the Québec toolkit well beyond PIPEDA's baseline. A good privacy program treats these as service requests with deadlines, not legal threats.

Info Source#

Info Source is the federal government's annual directory of information holdings, including personal information banks, for every federal institution. It exists so the public can exercise access rights under the Privacy Act and the Access to Information Act without guessing where records live. Institutions must keep their entries current.

IPC Ontario#

The Information and Privacy Commissioner of Ontario is the province's independent oversight body for access and privacy. It investigates complaints, issues binding orders, and promotes best practices for public bodies and health custodians. Ontario privacy practitioners read its orders the way lawyers read case law.

J

Joint investigation#

A joint investigation is when two or more privacy regulators pool their powers to investigate the same organization or practice at once. Canada's federal and provincial commissioners have run joint investigations into companies operating across jurisdictions. For organizations, it means one coordinated probe with combined enforcement weight rather than separate fights in each province.

Journalistic exemption (Law 25)#

Personal information collected, used, or communicated for journalistic purposes is carved out of key Law 25 obligations. The exemption protects newsgathering and publication, provided the material was lawfully obtained in the course of journalistic activity. It is about the activity, not the label, so calling a blog a newspaper does not automatically qualify.

Journalistic, artistic and literary exclusion (PIPEDA)#

PIPEDA does not apply to the collection, use, or disclosure of personal information for journalistic, artistic, or literary purposes, a carve-out that protects freedom of expression. News organizations rely on it when reporting stories that involve identifiable people. The exclusion is narrow: it covers the journalistic work itself, not a publisher's marketing or HR databases.

L

Law 25 (Loi 25)#

Law 25 is Québec's modernized private-sector privacy law (formally Bill 64, amending the Act respecting the protection of personal information in the private sector). It took full effect in phases from 2022 to 2024, adding mandatory PIAs, a default privacy officer, express consent rules for sensitive data, data portability, de-indexation rights, incident reporting, and fines up to $10 million or 2% of worldwide turnover. It is Canada's toughest provincial privacy law.

Law 25 guidance (CAI guides)#

The CAI publishes guides explaining how to apply Law 25, on topics like privacy impact assessments, consent, and incident notification. These are not statutes, but they are the regulator's stated expectations, and organizations ignore them at their own risk. When a compliance question is ambiguous, the guides are the first place practitioners look.

LCCJTI (Quebec IT framework act)#

LCCJTI is short for the Act to establish a legal framework for information technology. It gives electronic documents and signatures legal standing in Quebec and sets rules on the integrity, transferability, and retention of digital records. Privacy practitioners meet it where digitization meets evidence: how a record was created and kept affects whether it proves anything.

Least privilege#

Least privilege means giving each user and system only the access it needs to do its job, and nothing more. It limits the damage from a compromised account or a curious insider because most of the organization's data stays out of reach. It is one of the cheapest and most effective security principles in practice.

PIPEDA allows personal information to be collected or disclosed without consent when it is needed for legal proceedings, such as litigation, a regulatory hearing, or enforcing a legal right. Lawyers and organizations rely on it to gather and share evidence that a court or tribunal requires. The exception does not cover fishing expeditions; the information must genuinely relate to the proceedings.

LGPD (Brazil)#

Brazil's LGPD is the country's general data protection law, modeled closely on the EU GDPR with similar principles, individual rights, and a national regulator. It applies to organizations outside Brazil that handle Brazilians' personal data when offering them goods or services. Canadian businesses expanding into Latin America usually meet the LGPD first.

Limiting collection (PIPEDA Principle 4)#

Limiting collection is the fourth PIPEDA principle: collect only what is necessary for the identified purposes, and collect it fairly and lawfully. It is the statutory cousin of data minimization, pushing organizations to resist the urge to gather data just in case. Over-collection is one of the most common findings in regulator investigations.

Limiting use, disclosure and retention (PIPEDA Principle 5)#

Limiting use, disclosure and retention is the fifth PIPEDA principle, holding that personal information should be used and shared only for the purposes the person consented to. Once those purposes are fulfilled, the information must be destroyed or de-identified. It is the principle that turns a one-time collection into an ongoing obligation with an end date.

Lockbox (express instruction)#

A lockbox is a patient's express instruction under PHIPA to withhold or withdraw consent for the sharing of their personal health information for health care purposes. Custodians must respect it, subject to narrow overrides for emergencies or legal requirements. In practice it is implemented through flags in electronic health records that block specified providers from seeing the data.

M

Material privacy breach (federal)#

A material privacy breach is a breach involving federal personal information that creates a real risk of significant harm, such as identity theft or reputational damage. Treasury Board rules require institutions to report material breaches to the Privacy Commissioner and the Treasury Board Secretariat and to notify affected individuals. The materiality assessment must be documented even when the conclusion is no.

Meaningful consent is the Privacy Commissioner's standard that consent must be an informed choice, not a buried checkbox. Organizations have to explain what they collect, why, and who it goes to, in plain language, before asking. Consent that is uninformed or obtained through dark patterns can be treated as no consent at all.

MFIPPA (Ontario municipal)#

MFIPPA is Ontario's Municipal Freedom of Information and Protection of Privacy Act, covering municipalities, school boards, and local boards. It mirrors FIPPA's two halves, access to records and protection of personal information, at the local level. Requests to a city hall go through this statute.

Multi-factor authentication (MFA)#

Multi-factor authentication requires two or more proofs of identity at login: something you know, like a password, plus something you have or are, like a phone code or fingerprint. It blocks the vast majority of account-takeover attacks because stolen passwords alone are not enough. Regulators and insurers increasingly treat MFA as baseline security for sensitive systems.

N

Necessity (and proportionality)#

Necessity asks whether collecting this information is truly needed for the stated purpose, not merely useful or convenient. Law 25 requires collection be limited to what is necessary, and regulators apply a proportionality lens: the more intrusive the collection, the stronger the justification required. If you can't explain why you need it, you shouldn't collect it.

NIST AI Risk Management Framework#

The NIST AI Risk Management Framework is a voluntary guide from the US National Institute of Standards and Technology for managing AI risks, organized around govern, map, measure, and manage. It does not impose legal duties, but many organizations use it as a practical checklist for responsible AI. Canadian privacy teams often borrow it when building their AI governance programs.

Notification to the CAI (Law 25)#

The CAI is the Commission d'acces a l'information, Quebec's privacy and access regulator. Under Law 25, any confidentiality incident posing a serious risk of harm must be reported to it promptly, in addition to notifying affected individuals. The CAI keeps a register of incidents and can investigate what went wrong and order fixes.

O

OECD Privacy Guidelines#

The OECD Privacy Guidelines are a set of internationally agreed principles for protecting personal data, first adopted in 1980 and revised in 2013. They introduced ideas like purpose specification and openness that later appeared in PIPEDA, the GDPR, and many other laws. PIPEDA itself was drafted with these guidelines in mind.

OIPC Alberta#

The Office of the Information and Privacy Commissioner of Alberta oversees the province's public-sector, private-sector, and health privacy laws. It investigates complaints, conducts inquiries, and issues binding orders. Alberta is unusual in having a single commissioner cover all three regimes.

OIPC BC#

The Office of the Information and Privacy Commissioner for British Columbia oversees the province's access and privacy laws, including FIPPA, PIPA, and the health-sector statutes. It issues guidance, investigates complaints, and can order public bodies and organizations to comply. Its technology guidance is widely read across Canada.

Ombudsman model (OPC)#

The ombudsman model describes how the federal Privacy Commissioner has historically worked: investigating complaints, mediating resolutions, and issuing non-binding findings rather than orders. It favors persuasion and negotiated fixes over penalties. Critics say it lacks teeth, which is why proposed federal reforms aim to add order-making and fining powers.

Onward transfer#

An onward transfer is any further sharing of personal information after it first leaves your hands, from a vendor to its sub-processor or on to a partner. Each hop must stay within the original purposes and protections, which is why contracts should require consent or at least notice before data moves again. Losing track of onward transfers is how data ends up in places no one approved.

OPC (Office of the Privacy Commissioner of Canada)#

The Office of the Privacy Commissioner of Canada is the federal privacy watchdog, overseeing PIPEDA for the private sector and the Privacy Act for federal institutions. It operates largely as an ombudsman: it investigates complaints, issues findings, and seeks cooperation, though proposed reforms would add order-making powers and penalties. Its guidance shapes privacy practice nationwide.

OPC audit powers#

The Privacy Commissioner can audit an organization's privacy practices, either after receiving complaints that suggest systemic issues or on the Commissioner's own initiative. Audits can compel the production of records and examine how personal information is handled. Public audit reports are a strong motivator, since no organization wants its gaps published by the regulator.

OPC findings#

OPC findings are the published outcomes of the Commissioner's investigations into privacy complaints. They name the issue, assess whether the law was violated, and recommend fixes. While not court orders, findings carry reputational weight and often foreshadow where enforcement is heading.

OPC interpretation bulletins#

Interpretation bulletins are the Privacy Commissioner's published explanations of how the office reads specific PIPEDA provisions, from what counts as meaningful consent to how long breach records must be kept. They are not statutes, but organizations ignore them at their peril because they signal how investigations will be decided. Privacy programs use them as the practical layer between the law and daily operations.

OPC report of findings#

An OPC report of findings is the written outcome of a Privacy Commissioner investigation, setting out the facts, the analysis, and whether the organization complied with PIPEDA. Most reports end in non-binding recommendations rather than orders. A complainant who is unsatisfied can take the report to the Federal Court, which is where findings can turn into enforceable remedies.

Openness and transparency#

Openness is the duty to make your privacy practices visible and understandable: what you collect, why, who you share it with, and how people can exercise their rights. PIPEDA names it as a principle; Law 25 requires published governance policies and clear notices. Transparency isn't a banner, it's whether a normal person can actually understand what happens to their data.

Opt-out consent assumes the person agrees unless they take action to refuse, such as unchecking a box or calling to decline. PIPEDA permits it only in narrow circumstances: the information is not sensitive, the use is reasonable and expected, and the opt-out is clear and easy. Regulators have rejected opt-out approaches where any of those conditions failed.

Order-making powers (provincial commissioners)#

Order-making powers let some provincial privacy commissioners, such as those in Alberta, BC, and Québec, issue legally binding orders telling an organization what it must do or stop doing. This contrasts with the federal ombudsman model of non-binding recommendations. Organizations in those provinces face enforceable commands rather than advice alone.

P

Penal offences (Law 25)#

Law 25 creates penal offences for conduct like collecting, using, or disclosing personal information in breach of the law, and for knowingly obstructing the CAI. Penalties escalate for repeat offenders and are higher for legal persons than for individuals. Directors and officers can also be personally liable when they direct or authorize the offence.

Person carrying on an enterprise#

Under Quebec privacy law, this is the entity that collects and holds personal information in a business context. The phrase covers companies, partnerships, and solo operators, not just corporations. Law 25 places duties like consent, transparency, and security on this person, and their liability cannot be quietly shifted to a vendor.

Personal health information (PHI)#

Personal health information is identifying information about a person's health or health care: diagnoses, treatment records, health numbers, and even the fact that someone received care. Ontario's PHIPA and similar provincial laws give it stronger protection than general personal information. Custodians can only collect, use, or disclose it with consent or specific legal authority.

Personal information / renseignements personnels#

Personal information is any information about an identifiable individual, from a name and email to an IP address or purchase history, depending on context. Québec law phrases it as information that relates to a natural person and allows that person to be identified. It does not cover business contact details used for business purposes.

Personal information banks (PIBs)#

Personal information banks are Treasury Board's standardized descriptions of the personal information holdings of each federal institution, published so people can find records about themselves. They describe what is collected, why, and how long it is kept. When you file a Privacy Act access request, the relevant bank tells you where to look.

Personal Information International Disclosure Protection Act (Nova Scotia)#

This Nova Scotia statute limits the storage of and access to personal information by public bodies outside Canada. It requires public bodies to ensure their data stays under Canadian protection unless strict conditions are met. It is one of the strongest data-residency rules for a provincial public sector in the country.

Phased implementation (Law 25)#

Law 25's obligations came into force in three stages, phased in over 2022 to 2024, giving organizations time to adjust. Early measures included appointing a privacy officer and reporting serious incidents; later stages added rules on automated decisions, the right to portability, and express consent for sensitive information. Knowing which phase a rule belongs to explains why some obligations still feel new.

PHIA (Manitoba)#

Manitoba's Personal Health Information Act governs personal health information held by trustees like regional health authorities, hospitals, and health professionals. It sets rules for collection, use, and disclosure, and gives individuals access and correction rights. Manitoba's ombudsman and the Information and Privacy Adjudicator handle oversight.

PHIA (Newfoundland and Labrador)#

Newfoundland and Labrador's Personal Health Information Act covers personal health information held by custodians across the health system. It sets rules for collection, use, and disclosure, with access and correction rights for individuals. Oversight rests with the province's Information and Privacy Commissioner.

PHIA (Nova Scotia)#

Nova Scotia's Personal Health Information Act governs personal health information held by custodians across the health system. It gives individuals access and correction rights and restricts disclosure outside the circle of care. Oversight sits with the Office of the Information and Privacy Commissioner for Nova Scotia.

PHIPA (Ontario)#

PHIPA is Ontario's Personal Health Information Protection Act, governing personal health information held by health information custodians like hospitals, physicians, and labs. Patients have rights of access and correction, and custodians must keep audit logs of who viewed a record. Breaches posing risk require notification to the patient and, in serious cases, to the IPC.

PHIPAA (New Brunswick)#

PHIPAA is New Brunswick's Personal Health Information Privacy and Access Act, covering personal health information in the hands of custodians. Patients can access their records and request corrections, and custodians must safeguard the information. New Brunswick's Integrity Commissioner handles complaints.

Phishing#

Phishing is a scam in which an attacker impersonates a trusted sender, usually by email or text, to trick someone into handing over credentials or clicking a malicious link. It remains the most common way breaches begin, because one rushed click can bypass technical defenses. Training people to verify before acting is the main defense.

PIA / EIVP#

A privacy impact assessment (évaluation d'impact sur la vie privée) is a structured review of a new project or system to spot privacy risks before launch. Under Law 25, enterprises must conduct one before acquiring, developing, or overhauling an information system or electronic service involving personal information, and before communicating personal information outside Québec. The assessment must be proportionate to the sensitivity of the data and the risks involved.

PIA for technological products (Law 25)#

A privacy impact assessment is a structured review an organization does before a project that affects personal information. Under Law 25 it is mandatory for any technological product or service offered to the public that collects, uses, or communicates personal information. It is also required before communicating information outside Quebec, which makes PIAs a recurring discipline rather than a one-time form.

PIPEDA#

PIPEDA (the Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, built on ten fair information principles. It applies wherever provinces lack “substantially similar” legislation, Québec, B.C., and Alberta have their own. It requires meaningful consent, limits collection and retention, and gives individuals access rights; proposed reforms would modernize it.

PIPL (China)#

China's PIPL is the country's comprehensive privacy law, in force since 2021. It echoes the GDPR on consent, purpose limits, and individual rights, but it pairs those duties with strict rules on moving data out of China. Multinationals operating in China often face the hardest compliance puzzle of any market there.

Prescribed entity#

A prescribed entity is an organization designated by regulation under PHIPA to collect and use personal health information for health system planning, evaluation, or resource allocation without individual consent. Ontario Health and ICES are examples. Prescribed entities face strict review requirements and must have their information practices approved by the Information and Privacy Commissioner.

Prescribed person#

A prescribed person is designated by regulation under PHIPA to compile and maintain specific health registries, such as cancer or cardiac registries, using personal health information without individual consent. The designation comes with conditions on collection, use, disclosure, and security. It is a narrower role than a prescribed entity, tied to a specific registry purpose.

Privacy Act (federal)#

The Privacy Act governs how federal government institutions collect, use, and disclose personal information about individuals. It gives people the right to access their own records held by institutions and to request corrections. Complaints go to the Privacy Commissioner of Canada, and unresolved refusals can be taken to Federal Court.

Privacy Act complaint (OPC)#

A Privacy Act complaint is filed with the Office of the Privacy Commissioner when a federal institution mishandles personal information or mishandles an access request. The OPC investigates and issues findings and recommendations, which are not binding orders. If the institution refuses access, the complainant can escalate to the Federal Court.

Privacy by default#

Privacy by default means the most privacy-protective settings apply automatically, without the user having to change anything. It is a companion to privacy by design: the system should not require people to opt out of data collection they never asked for. Both PIPEDA guidance and Law 25 expect organizations to think this way.

Privacy by design#

Privacy by design means building privacy into products and processes from the start rather than bolting it on later. The concept, seven foundational principles from Ontario's former commissioner Ann Cavoukian, calls for proactive, default-private, embedded safeguards. Law 25's mandatory PIAs before new systems are, in effect, privacy-by-design requirements with teeth.

Privacy management program (OPC)#

A privacy management program is the OPC's framework for building accountability into an organization, with named leadership, policies, training, and monitoring scaled to the organization's size and risk. The Commissioner has said a documented program is the expected evidence of compliance, not an optional extra. It is the backbone that due-diligence questionnaires and investigations both ask to see.

Privacy notice vs. privacy policy#

A privacy notice is the point-of-collection explanation: what you're collecting right now, why, and what choices the person has. A privacy policy is the organization's overall governance document covering all its practices. Law 25 goes further, requiring published governance rules (roles, retention, complaint handling, security). Notices face the user; policies face the auditor.

Privacy officer (responsable de la protection des renseignements personnels)#

The privacy officer is the person accountable for an organization's privacy program. Under Law 25, the default is the person with the highest authority in the enterprise, who may delegate the role in writing; the title and contact details must be published. This person oversees the governance framework, handles access requests, and approves PIAs.

Privacy paradox#

The privacy paradox is the gap between what people say about privacy and what they do: surveys show deep concern, yet people routinely trade data for small conveniences. It does not mean people do not care; it usually means the choices are designed badly or the costs are hidden. Regulators use it to justify stronger defaults rather than relying on informed consent alone.

Privacy risk reviews (federal)#

Privacy risk reviews are the federal government's scaled assessments for initiatives that touch personal information, ranging from checklists to full privacy impact assessments. TBS requires them before launching new programs, systems, or data-sharing arrangements. The review must identify risks and mitigations and be updated when the initiative changes materially.

Private right of action#

A private right of action lets individuals sue directly for privacy violations instead of relying on a regulator. Law 25 gives Québecers this right, including minimum damages (commonly cited as $1,000 per person) and the possibility of class actions. It turns privacy rights into courtroom leverage.

Proactive disclosure#

Proactive disclosure is the federal practice of publishing certain government records automatically, without waiting for access requests: travel and hospitality expenses, contracts, grants, and briefing note titles. It is required by the Access to Information Act for institutions and ministers' offices. The goal is transparency by default rather than transparency on demand.

Processor / agent / service provider#

A processor is a third party that handles personal information on an organization's behalf, a cloud host, payroll provider, or analytics vendor. Québec's Law 25 calls this party an agent or mandatary acting under a written agreement with required safeguards. The key rule everywhere: the organization stays accountable, and the vendor may only use the data for the contracted purpose.

Productivity monitoring#

Productivity monitoring is software that measures how employees work: active hours, application usage, task completion rates, and idle time. Privacy regulators view it as high-risk surveillance that needs a demonstrable business purpose, clear notice, and the least intrusive means available. Continuous screenshots or keystroke logging for all staff, without justification, is the pattern that draws enforcement.

Professional secrecy (Quebec)#

In Quebec, professional secrecy is the duty of members of regulated professions to keep client confidences. It is broader than common-law solicitor-client privilege because it covers many professions, from accountants to physicians. When it conflicts with disclosure demands, overriding it normally requires a legal basis.

Profiling#

Profiling is using personal information to evaluate characteristics or behavior, credit scoring, ad targeting, employee risk flags. Law 25 requires organizations to inform people when technology identifies, locates, or profiles them and to provide a way to deactivate profiling functions. Profiling that feeds automated decisions gets extra transparency duties.

Pseudonymization#

Pseudonymization replaces identifiers with codes or tokens so data can't be linked to a person without a separate key. It reduces risk and is good security hygiene, but the data can still count as personal information because re-identification is possible. Don't confuse it with anonymization, which is meant to be irreversible.

Publication of CAI decisions#

The CAI publishes its decisions and orders, building a public record of how the law is interpreted. For practitioners, these rulings are the most useful guidance available: they show what the regulator actually penalizes and orders. Watching them is how organizations learn the practical boundaries of Law 25.

Publicly available information#

Publicly available information is personal information the law excludes from consent requirements because it is public by law, land registry entries, court records, professional directories. Québec's Law 25 keeps a narrow statutory list, and “publicly available” does not mean “anything you can find online.” Scraping the web is not a consent strategy.

Publishing privacy officer contact (Law 25)#

Every organization subject to Law 25 must designate a person responsible for protecting personal information and publish their title and contact information, typically on the website. By default that person is the head of the enterprise, unless the role is formally delegated. Regulators treat a missing contact line as an early sign the privacy program is thin.

Purpose limitation#

Purpose limitation means using personal information only for the purposes you identified when collecting it, unless you get fresh consent or the law allows otherwise. Law 25 requires purposes to be established before collection; PIPEDA mirrors this in its principles. New purpose, new consent.

Q

Quebec health records (LSSSS)#

Health and social services records in Quebec are governed by the Act respecting health services and social services (LSSSS), which gives them a dedicated confidentiality regime. It sets who may access clinical records, for what purposes, and how consent works in care settings. General privacy rules apply too, but the LSSSS provisions take the lead for patient files.

Quebec requires express, informed consent for most collection, use, and communication of personal information. That is the opt-in model: the organization asks first and proceeds only after a clear yes. Pre-ticked boxes, silence, or buried terms do not count as consent.

R

Ransomware#

Ransomware is malicious software that encrypts an organization's files and demands payment for the decryption key. Attacks often start with a phishing email or an unpatched vulnerability, and modern gangs also steal the data first so they can threaten to publish it. Under Canadian privacy law, a ransomware incident that exposes personal information generally triggers breach notification duties.

Real risk of significant harm (RROSH)#

Real risk of significant harm is the legal threshold that triggers mandatory breach notification under PIPEDA. It means the breach could plausibly cause harm like identity theft, financial loss, or damage to reputation, and a merely theoretical possibility is not enough. If an organization reasonably concludes the threshold is met, it must notify the Privacy Commissioner and the affected individuals as soon as feasible.

Reasonable person test#

The reasonable person test asks whether a reasonable person would consider a collection, use, or disclosure appropriate in the circumstances. PIPEDA's section 5(3) makes it an explicit limit: even with consent, inappropriate purposes are unlawful. It is the law's common-sense backstop.

Red-teaming (AI)#

Red-teaming an AI system means deliberately attacking it to find failures: jailbreaking its safety filters, extracting training data, or tricking it into harmful outputs. Borrowed from cybersecurity, the practice is now a standard part of responsible AI deployment. Organizations document the findings and fix them before, or shortly after, launch.

Reference checks (privacy)#

Reference checks are employer inquiries to a candidate's former employers or named referees about work history and performance. They need the candidate's consent, and referees should stick to job-relevant facts because defamation and privacy complaints are real risks. Candidates also have access rights to the resulting notes under most Canadian privacy laws.

Referral marketing (CASL)#

Referral marketing is when a business asks existing customers to send its commercial messages to their friends or contacts. CASL does not bless this practice: each message still needs the recipient's own consent, and the business can be liable for messages its referrers send on its behalf. Programs that reward customers per referral are especially risky, because the volume and targeting are the company's doing.

Research exemption (Law 25)#

Law 25 allows personal information to be used or communicated without consent for a study or research project, or for the production of statistics, under strict conditions. The receiving organization must apply to the CAI for authorization and demonstrate that the project serves the public interest. Consent remains the default; the exemption is a narrow path with paperwork, not a shortcut.

Retention periods (Law 25)#

Law 25 requires organizations to set rules for how long personal information is kept, and to destroy or anonymize it once the purpose is fulfilled. The retention rules themselves must be established up front, not invented after the fact. Data kept just in case has no home under this regime.

Retention schedule#

A retention schedule sets how long each type of personal information is kept and when it must be destroyed or anonymized. Law 25 requires enterprises to establish retention rules as part of their governance framework. Keep data only as long as needed for its purpose, then delete or anonymize it.

Right of access#

The right of access lets you see the personal information an organization holds about you and learn how it was collected, used, and disclosed. Both PIPEDA and Law 25 recognize it. Organizations must respond within 30 days, with limited exceptions.

Right to be informed (Law 25)#

This is the right to know what an organization is doing with your personal information, in clear language and at the point of collection. Law 25 lists what the organization must disclose, such as the purposes, the categories of information collected, and the categories of people who can access it. A vague privacy notice that leaves you guessing fails this duty.

Right to erasure / de-indexation#

The right to erasure lets individuals ask that their personal information be deleted once its purpose is fulfilled, subject to legal retention duties. Law 25 added both erasure and the right to have hyperlinks to the information de-indexed, effective September 2024. PIPEDA has no equivalent erasure right yet.

Right to rectification#

The right to rectification lets you ask an organization to correct inaccurate, incomplete, or ambiguous personal information. Law 25 gives it expressly; PIPEDA covers it through its accuracy and challenge principles. Organizations must pass corrections on to anyone they shared the data with, where feasible.

Right to submit observations (automated decisions)#

When a decision about you is made exclusively through automated processing, Law 25 gives you the right to be informed of that fact. You can then submit observations about the decision and demand a human review. The organization must tell you how to exercise these rights when it informs you of the decision.

S

Safeguards principle (PIPEDA)#

The safeguards principle requires organizations to protect personal information with security measures appropriate to its sensitivity. That means a mix of physical, organizational, and technological safeguards, from locked filing cabinets to encryption and access controls. A breach does not automatically prove the safeguards failed, but weak or absent safeguards will count against the organization.

Sanction administrative pécuniaire#

A sanction administrative pécuniaire (SAP) is a monetary administrative penalty the CAI can impose directly for Law 25 violations, no court required. They reach up to $10 million or 2% of worldwide turnover for organizations ($50,000 for individuals), with penal fines up to $25 million or 4% through the courts. The CAI published a framework explaining how it calibrates them.

SB 53#

SB 53 is a California law, the Transparency in Frontier Artificial Intelligence Act, requiring developers of the largest AI models to publish safety frameworks and report critical safety incidents to the state. Signed in 2025, it created the first mandatory AI incident-reporting regime in a major jurisdiction. Even companies outside California watch it closely, because frontier models are deployed everywhere.

Schrems II#

Schrems II is a 2020 ruling of the EU's top court that struck down the EU-US Privacy Shield as a lawful way to move personal data to the United States. The court found US surveillance law did not give Europeans protection comparable to the GDPR, so every transfer now needs an individual check that the destination country's law does not undermine the contract terms. Canadian organizations that send EU data to US vendors still have to do this transfer risk assessment.

Secondary use of personal information#

A secondary use is any use beyond the original, stated purpose of collection, like reusing support tickets to train a model. Privacy law generally requires fresh consent for secondary uses. This is where purpose limitation bites hardest, and where PIAs earn their keep.

Sender identification (CASL)#

Sender identification is CASL's requirement that every commercial electronic message name the sender and, where applicable, the person on whose behalf it is sent, plus contact details like a mailing address. The point is that recipients can reach someone responsible. Masked or misleading sender information makes the message non-compliant even if consent existed.

For sensitive personal information, such as health, financial, biometric, or intimate details, Law 25 requires express consent. Implied consent is not enough, and the organization must state the purposes clearly before asking. The strictness matches the harm: a leak of sensitive data hurts more than a leak of a phone number.

Sensitive personal information#

Sensitive personal information is data whose disclosure could cause serious harm or embarrassment: health, financial, biometric, location, or data about children and other intimate details. Law 25 requires express consent before collecting it; PIPEDA scales consent to sensitivity. When in doubt, treat it as sensitive.

Serious injury (confidentiality incident threshold)#

Serious injury is the harm threshold that triggers mandatory notification under Law 25: the CAI and affected individuals must be notified when an incident presents a risk of serious injury. Regulators weigh the sensitivity of the data, potential malicious use, and who was affected. When uncertain, organizations are expected to err toward notifying.

Social engineering#

Social engineering is manipulating people into breaking security: impersonating IT support to get a password, inventing an urgent pretext, or exploiting trust. It works on psychology rather than software, which is why even well-defended organizations fall for it. Privacy programs treat it as a human risk that policies alone cannot eliminate.

Standard contractual clauses (SCCs)#

Standard contractual clauses are pre-written contract terms approved by the European Commission that an EU organization uses with a foreign partner to make a data transfer lawful under the GDPR. They lock in protections like purpose limits, security duties, and rights for the people whose data moves. Because Canada's commercial adequacy finding does not cover everything, SCCs still appear in contracts for things like transfers to processors outside Canada.

Statement of disagreement#

A statement of disagreement is a short written note a patient can require a custodian to attach to their record when a correction request is refused. It states the patient's position in their own words, up to a length the custodian sets. Anyone the record is later disclosed to must receive the statement along with it.

Sub-processor#

A sub-processor is a vendor hired by your vendor, forming a chain of organizations that handle personal information downstream of you. Accountability follows the data, so the original organization needs visibility into and contractual control over sub-processors. Surprise sub-processors discovered after a breach are a classic sign the vendor management program was not working.

Substantially similar legislation#

Substantially similar legislation is a provincial privacy law that the federal government has recognized as comparable to PIPEDA, currently those of Alberta, British Columbia, and Québec. Where one of these laws applies to an activity, PIPEDA steps aside for that activity. For privacy professionals, this is the switch that moves compliance from the federal Commissioner to a provincial regulator.

Substitute decision-maker#

A substitute decision-maker is the person authorized to make health privacy decisions for someone who lacks capacity, chosen from PHIPA's ranked list: spouse or partner, then child or parent, then other relatives, and so on. The substitute must act in the person's best interests and follow any known wishes. Health providers must verify the person is the highest-ranked available and willing.

Surveillance capitalism#

Surveillance capitalism describes a business model in which companies extract behavioral data from people's lives and sell predictions about their future behavior, mostly to advertisers. The term was popularized by Shoshana Zuboff to argue that this model treats human experience as free raw material. It is the sharpest critique of the economics behind data-hungry platforms.

Synthetic data#

Synthetic data is artificial data generated to mimic the statistical properties of real data without containing real people's information. It is used to train and test AI systems when using real personal data would be risky or unlawful. It is not automatically privacy-safe, though: badly generated synthetic data can still leak details of the originals.

T

Tabletop exercise#

A tabletop exercise is a discussion-based rehearsal of an incident: the team walks through a fictional breach scenario and talks through each decision without touching real systems. It surfaces gaps in the response plan, like unclear roles or missing contacts, before a real crisis does. Most privacy teams run at least one a year.

Related insight: Breach Tabletop simulator

TBS Directive on Privacy Practices#

The Treasury Board Secretariat's Directive on Privacy Practices sets binding rules for how federal institutions manage personal information, from collection to breach response. It requires privacy impact assessments for new programs, designated privacy officials, and regular reviews of personal information banks. It turns the Privacy Act's principles into operational requirements across government.

Third party#

A third party is any person or organization outside the enterprise and its agents, including vendors, partners, and acquirers. Law 25 uses “communication” for sharing with third parties, which generally needs consent and always needs assessment before crossing Québec's borders. Contracts with third parties must spell out safeguards, limits, and audit rights.

Tokenization#

Tokenization replaces sensitive data, like a card number, with a meaningless substitute token, while the real value is stored securely elsewhere. Systems that only ever see tokens cannot leak the originals if breached. It is widely used in payments and is a practical way to limit what a breach can expose.

Training data (AI privacy)#

Training data is the information an AI model learns from: documents, images, recordings, and sometimes personal data scraped or licensed at scale. From a privacy view it is risky because models can memorize and later reveal individuals' details that were in the training set. Canadian organizations training models on customer data need a lawful basis for that use, not just for collecting it.

Transfers for processing (cross-border guidance)#

Transfers for processing refers to sending personal information to a service provider in another country for handling, such as cloud hosting or analytics, which the OPC treats as a use of the information rather than a disclosure. The organization stays accountable for the information while it is abroad, and must assess the risks and use contracts to keep protections equivalent. Québec's Law 25 takes a stricter transfer assessment approach, so cross-border plans often need a provincial lens too.

U

UDHR Article 12#

Article 12 of the Universal Declaration of Human Rights states that no one shall be subjected to arbitrary interference with their privacy, family, home, or correspondence. Written in 1948, it is the moral root of privacy as a human right in international law. Courts and regulators still cite it when framing privacy protections.

UK GDPR#

The UK GDPR is Britain's version of the European GDPR, kept on the books after Brexit with UK-specific tweaks. It governs organizations operating in the UK much like the EU GDPR governs those in the EU, with the same core duties around consent, rights, and breach reporting. A Canadian company serving UK customers answers to both the EU GDPR and the UK GDPR if it also touches EU data.

Unsolicited Telecommunications Rules (CRTC)#

The CRTC's Unsolicited Telecommunications Rules ban most telemarketing calls and faxes to numbers on the National Do Not Call List and set calling-time and identification rules for all telemarketers. Exemptions exist for existing business relationships, registered charities, political parties, surveys, and newspapers. The CRTC enforces them with the same administrative penalty toolkit as CASL.

Unsubscribe mechanism (CASL)#

The unsubscribe mechanism is how recipients tell a sender to stop commercial electronic messages, and CASL requires one on every commercial electronic message. The mechanism must be easy to use, such as a reply-to address or a link, and the sender must honor it within 10 business days. After that point, further messages need fresh express consent.

V

Vendor due diligence#

Vendor due diligence is the vetting an organization does before and during a vendor relationship that touches personal information: reviewing the vendor's security posture, privacy practices, sub-processors, and incident history. It turns accountability from a slogan into a buying decision, since the organization remains responsible for what its vendors do with the data. Regulators increasingly ask to see the due-diligence file after a vendor-caused breach.

Video surveillance#

Video surveillance collects personal information whenever it captures identifiable people. Regulators expect necessity and proportionality: cameras must serve a legitimate purpose that less intrusive measures can't achieve, with clear signage informing people they're being recorded. Footage needs retention limits and access controls like any other personal information.

Voluntary breach notification (PIPEDA)#

Voluntary breach notification happens when an organization tells affected individuals about a breach even though the real risk of significant harm threshold was not met. Organizations often do this for transparency or contractual reasons, or because caution is cheaper than being wrong. PIPEDA does not require it, but nothing stops an organization from notifying anyway.

Voluntary Code of Conduct for Generative AI (Canada)#

Canada's voluntary code of conduct for generative AI asks developers and deployers to follow responsible practices, like testing for bias and being transparent about AI-generated content. It is not law, but organizations signed up to it to show good faith while formal regulation was pending. Signing it was pitched as a trust signal, not a compliance shield.

W

Whistleblower disclosure (PIPEDA)#

PIPEDA permits disclosing personal information without consent when the disclosure is made to report that an organization or individual may have broken the law, known as a whistleblower disclosure. The person making the disclosure is shielded from being treated as breaching confidentiality in the process. It gives employees and others a lawful channel to flag wrongdoing to the right authorities.

Workplace investigations (privacy)#

Workplace investigations into harassment, theft, or misconduct routinely involve collecting personal information about employees: interviews, emails, access logs, and sometimes surveillance. Privacy law requires the collection to be reasonable and limited to what the investigation needs, with employees told as much as possible without tipping off wrongdoers. Covert surveillance is only justified in exceptional cases with evidence of wrongdoing.

Written service provider agreement (Law 25)#

Before giving personal information to a service provider or mandatee, the organization must put the arrangement in writing. The agreement must describe the measures the provider will take, such as security safeguards, and confirm the provider will use the information only for the mandate. Accountability does not follow the data out the door.

Z

Zero-day vulnerability#

A zero-day vulnerability is a software flaw that attackers are exploiting before the vendor has released a fix, named for the zero days of warning. It is dangerous because the usual defense, patching, does not yet exist. Organizations respond by applying emergency mitigations and watching for signs of compromise.

Definitions only get you so far.

If you're turning any of these concepts into an actual program — governance, PIAs, consent, breach readiness — I help organizations do exactly that.

Talk to me about privacy