Personal Information Protection and Electronic Documents Act | 2000, c. 5 — Canada law | Esheria

Personal Information Protection and Electronic Documents Act

This Part sets privacy rules for organizations handling personal information, including when they may collect, use, disclose, access, and must report breaches.

Jurisdiction
Canada
Instrument
Act or statute
Citation
2000, c. 5
Version
26 May 2026
Language
en
Official source
View official record ↗
access requests audit breach notification complaints and enforcement compliance confidentiality data mobility electronic commerce information sharing personal information personal information disclosure whistleblowing

Statute overview

About this statute

This Part sets privacy rules for organizations handling personal information, including when they may collect, use, disclose, access, and must report breaches. The Commissioner can audit an organization’s personal information practices and use related powers, but must keep most obtained information confidential. Organizations and employers are restricted from obstructing audits or retaliating against whistleblowers. Organizations must disclose an individual’s personal information to a designated organization when requested, if both organizations are in a data mobility framework and the disclosure is required by the regulations.

LexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.