🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CA-NB v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-05

New Brunswick, Canada

CA-NB schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 36 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
18Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

New Brunswick's data-protection posture tightened this cycle on the enforcement and redress track: Bill 46, An Act to Amend the Right to Information and Protection of Privacy Act, received Royal Assent in the 58th Legislature, 1st Session. The precise commencement date of the amendment was not resolved this cycle, but the Royal Assent itself is confirmed. New Brunswick has no provincial private-sector data-protection statute; private-sector commercial activity in the province is governed directly by the federal Personal Information Protection and Electronic Documents Act (PIPEDA), while Ombud NB oversees only public-sector information and privacy matters under the Right to Information and Protection of Privacy Act (RTIPPA). This bifurcated coverage, thinner than in provinces with substantially similar private-sector laws such as Alberta, British Columbia, or Quebec, is the structural backdrop against which the Bill 46 amendment should be read.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Regulator identity, governing instruments and material/territorial scope are clearly documented across multiple official OPC sources.

Primary frameworkPIPEDA (federal, private sector) + Right to Information and Protection of Privacy Act, SNB 2009 c R-10.6 (public sector) + Personal Health Information Privacy and Access Act, SNB 2009 c P-7.05 (health sector)
Traffic-light rationale — GreenRegulator identity, governing instruments and material/territorial scope are clearly documented across multiple official OPC sources.

Sub-modules (5)

Regulator And AuthorityGreen

OPC enforces PIPEDA nationally including in NB; the NB Ombud separately enforces RTIPPA (public sector) and PHIPAA (health sector).

Claims (2):

  • Office of the Privacy Commissioner of Canada (OPC) oversees compliance with PIPEDA, the federal private-sector privacy law applicable to commercial-activity personal information handling in New Brunswick. Central M1 regulator-identity claim. Challenger f-001 flagged an internal metadata inconsistency (0 T1-T3 sources declared vs. Confirmed rating) — escalated to gdpri-int-1 for human verification; underlying OPC government source independently corroborates the substance of the claim itself.
  • Office of the Ombud for New Brunswick oversees and enforces RTIPPA (NB public-sector privacy law) and PHIPAA (NB health-sector privacy law). Also implicated by Challenger f-001 metadata inconsistency; escalated to gdpri-int-1.

Act And InstrumentsGreen

Three instruments together constitute NB's regime: PIPEDA, RTIPPA, and PHIPAA.

Claims (1):

  • PIPEDA, RTIPPA and PHIPAA (NB three-instrument framework) together constitute New Brunswick's data-protection regime: PIPEDA (federal, private-sector commercial activity), RTIPPA (NB public bodies), PHIPAA (NB health information custodians). Foundational M1 architecture claim; layered federal/provincial construct, no single omnibus NB statute.

Material ScopeGreen

PIPEDA's commercial-activity scope fills NB's private-sector gap since no NB-specific substantially-similar private sector statute exists.

Claims (2):

  • PIPEDA applies to private-sector organizations across Canada, including New Brunswick, collecting, using or disclosing personal information in commercial activity. Material scope anchor claim.
  • New Brunswick has not enacted a general private-sector privacy statute deemed 'substantially similar' to PIPEDA (unlike AB, BC, QC); PIPEDA therefore continues to govern private-sector commercial data outside the health sector. Sub-national divergence signal: NB is a PIPEDA-default province.

Territorial ScopeGreen

PIPEDA applies to any business handling personal information crossing provincial/national borders regardless of home province.

Claims (1):

  • PIPEDA applies regardless of home province to businesses operating in Canada that handle personal information crossing provincial or national borders in commercial activity. Territorial scope claim.

Regulator Registration And FilingRed

No general controller registration or filing regime was identified for NB under PIPEDA, RTIPPA, or PHIPAA in this research pass.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative124 words

New Brunswick's data-protection position is a layered federal/provincial construct rather than a single provincial omnibus statute. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs private-sector commercial-activity data across the province because New Brunswick has not enacted a general private-sector statute deemed 'substantially similar' to PIPEDA (unlike Alberta, BC and Quebec). Two New Brunswick statutes overlay this: the Right to Information and Protection of Privacy Act (RTIPPA) for public bodies, and the Personal Health Information Privacy and Access Act (PHIPAA) for health information custodians (the latter deemed substantially similar to PIPEDA for that sector). Both provincial statutes are overseen by the Office of the Ombud for New Brunswick; PIPEDA is overseen federally by the Office of the Privacy Commissioner of Canada (OPC).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — Office of the Privacy Commissioner of Canada (OPC) oversees compliance with PIPEDA, the federal private-sector privacy law applicable to commercial-activity personal information handling in New Brunswick. Central M1 regulator-identity claim. Challenger f-001 flagged an internal metadata inconsistency (0 T1-T3 sources declared vs. Confirmed rating) — escalated to gdpri-int-1 for human verification; underlying OPC government source independently corroborates the substance of the claim itself.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — Office of the Ombud for New Brunswick oversees and enforces RTIPPA (NB public-sector privacy law) and PHIPAA (NB health-sector privacy law). Also implicated by Challenger f-001 metadata inconsistency; escalated to gdpri-int-1.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA, RTIPPA and PHIPAA (NB three-instrument framework) together constitute New Brunswick's data-protection regime: PIPEDA (federal, private-sector commercial activity), RTIPPA (NB public bodies), PHIPAA (NB health information custodians). Foundational M1 architecture claim; layered federal/provincial construct, no single omnibus NB statute.observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA applies to private-sector organizations across Canada, including New Brunswick, collecting, using or disclosing personal information in commercial activity. Material scope anchor claim.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — New Brunswick has not enacted a general private-sector privacy statute deemed 'substantially similar' to PIPEDA (unlike AB, BC, QC); PIPEDA therefore continues to govern private-sector commercial data outside the health sector. Sub-national divergence signal: NB is a PIPEDA-default province.observed
  6. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA applies regardless of home province to businesses operating in Canada that handle personal information crossing provincial or national borders in commercial activity. Territorial scope claim.observed

#

Lawful bases, consent and sensitive-data coverage are well evidenced; anonymisation/pseudonymisation specifics are an evidence gap.

Primary frameworkPIPEDA Schedule 1 (10 Fair Information Principles)
Traffic-light rationale — AmberLawful bases, consent and sensitive-data coverage are well evidenced; anonymisation/pseudonymisation specifics are an evidence gap.

Sub-modules (4)

Lawful BasesGreen

The 10 Schedule 1 principles operate as PIPEDA's lawful-processing framework.

Claims (1):

  • PIPEDA Schedule 1 requires businesses to follow 10 fair information principles as the lawful-processing framework. No GDPR Art.6-style discrete legal-basis list; principles-based structure.

Special CategoriesAmber

PIPEDA's personal information definition explicitly includes sensitive categories such as medical records and ethnic origin.

Claims (1):

  • PIPEDA's personal information definition explicitly includes sensitive categories such as medical records and ethnic origin. No discrete GDPR Art.9-style special-category regime; do not GDPR-lens this. Assert on PIPEDA's own terms.

Pseudonymisation And AnonymisationRed

No PIPEDA-specific anonymisation/pseudonymisation safe-harbour provisions were located; searched OPC guidance pages and summary-of-laws resources without a definitive NB-applicable standard.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative69 words

PIPEDA's Schedule 1 sets out ten fair information principles functioning as NB's private-sector lawful-processing framework, with a 2015 (Digital Privacy Act) amendment clarifying the standard for valid/meaningful consent. PIPEDA's definition of personal information expressly captures sensitive categories (medical records, ethnic origin, etc.), though PIPEDA does not use a discrete 'special category' regime analogous to GDPR Art 9. Pseudonymisation/anonymisation safe-harbour rules specific to PIPEDA were not located in this pass.

Sources and claims (3)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA Schedule 1 requires businesses to follow 10 fair information principles as the lawful-processing framework. No GDPR Art.6-style discrete legal-basis list; principles-based structure.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA (post-2015 Digital Privacy Act amendment) requires consent to be informed such that individuals understand the nature, purpose and consequences of the collection, use or disclosure. Meaningful-consent standard.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA's personal information definition explicitly includes sensitive categories such as medical records and ethnic origin. No discrete GDPR Art.9-style special-category regime; do not GDPR-lens this. Assert on PIPEDA's own terms.observed

#

Only the access-right sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Primary frameworkPIPEDA Schedule 1, Principle 9 (Individual Access); RTIPPA (public sector access/correction, NB)
Traffic-light rationale — RedOnly the access-right sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Sub-modules (5)

Access RightAmber

PIPEDA permits refusal of access only in narrow, enumerated circumstances (e.g., solicitor-client privilege).

Claims (1):

  • PIPEDA s.9(3) permits refusal of access only in limited enumerated circumstances, e.g. solicitor-client privilege or formal dispute-resolution process information. Only well-evidenced data_subject_rights sub-module this cycle; rectification, restriction, portability and deadlines remain gaps (gdpri-int-2).

Rectification And ErasureRed

No PIPEDA/RTIPPA-specific rectification or erasure provision text was retrieved in this pass; searched OPC guidance and provincial-law summary pages.

Restriction And ObjectionRed

No restriction/objection-specific provision was retrieved for PIPEDA, RTIPPA or PHIPAA in this pass.

Data PortabilityRed

No portability right currently exists under PIPEDA; a proposed portability mechanism under the Consumer Privacy Protection Act (part of Bill C-27) never came into force after the Bill died on prorogation.

Deadlines And Response WindowsRed

Statutory response-deadline specifics for PIPEDA/RTIPPA/PHIPAA access requests were not retrieved in this pass.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative43 words

PIPEDA's access-right framework (with narrow statutory exceptions under s.9(3)) is documented, but rectification/erasure, restriction/objection, portability and statutory response-deadline specifics under PIPEDA/RTIPPA/PHIPAA were not confirmed in this research pass; Canada's proposed portability and ADM-contest rights (under the now-dead Bill C-27 CPPA) never took effect.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA s.9(3) permits refusal of access only in limited enumerated circumstances, e.g. solicitor-client privilege or formal dispute-resolution process information. Only well-evidenced data_subject_rights sub-module this cycle; rectification, restriction, portability and deadlines remain gaps (gdpri-int-2).observed

#

Breach notification, accountability and security-safeguard duties are strongly evidenced; DPO/ROPA/joint-controller sub-modules are gaps because PIPEDA does not impose GDPR-style discrete obligations of this kind.

Primary frameworkPIPEDA (breach-of-security-safeguards regime, s.10.1; Schedule 1 Principles 4.1 (Accountability) and 4.7 (Safeguards)); PHIPAA (NB health-sector breach notification)
Traffic-light rationale — AmberBreach notification, accountability and security-safeguard duties are strongly evidenced; DPO/ROPA/joint-controller sub-modules are gaps because PIPEDA does not impose GDPR-style discrete obligations of this kind.

Sub-modules (7)

Accountability And DpiaAmber

PIPEDA's accountability principle keeps organizations responsible for information transferred to third parties for processing.

Claims (1):

  • PIPEDA's accountability principle keeps organizations responsible for personal information transferred to a third party for processing. No formal DPIA statutory obligation distinct from this principle.

Dpo RequirementsRed

No PIPEDA/RTIPPA/PHIPAA statutory DPO-appointment threshold was located in this pass.

Ropa RequirementsRed

No discrete records-of-processing (ROPA) obligation analogous to GDPR Art 30 was located under PIPEDA, RTIPPA or PHIPAA.

Joint Controller ArrangementsRed

No joint-controller-specific statutory framework was located under PIPEDA, RTIPPA or PHIPAA in this pass.

Security MeasuresGreen

PIPEDA's breach-of-security-safeguards definition ties directly to Schedule 1 Principle 4.7 security obligations.

Claims (1):

  • PIPEDA's 'breach of security safeguards' definition is defined by reference to loss of, unauthorized access to, or unauthorized disclosure of personal information from a Schedule 1 Principle 4.7 safeguards breach or failure to establish safeguards. Security-safeguards anchor for M4.

Breach NotificationGreen

PIPEDA's RROSH-based mandatory breach reporting/notification regime and its penalty structure are well documented; NB's PHIPAA imposes parallel health-sector breach-notification duties.

Claims (3):

  • PIPEDA requires reporting to OPC and notifying affected individuals of any breach of security safeguards posing a real risk of significant harm (RROSH). Best-evidenced M4 sub-module; RROSH threshold central to PIPEDA breach regime.
  • PIPEDA breach-duty offence provision penalizes knowing non-compliance with fines of up to $100,000, prosecuted federally rather than administratively imposed by OPC. Materially weaker deterrent than GDPR turnover-based fines; see key_judgments.
  • New Brunswick (PHIPAA) imposes, alongside ON/NS/NL, mandatory breach notification/reporting obligations on health-sector custodians. Sub-national health-sector overlay; do not collapse into a single Canada-wide rule.

Retention And DisposalGreen

PIPEDA requires two-year retention of breach records for OPC inspection.

Claims (1):

  • PIPEDA requires retention of breach records for two years, available to OPC upon request. Retention duty tied to breach-record-keeping.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative105 words

Breach notification is the best-evidenced duty in this module: PIPEDA requires reporting to the OPC and notifying affected individuals where a breach poses a 'real risk of significant harm' (RROSH), with knowing non-compliance punishable by fines up to $100,000 (prosecuted federally, not administratively imposed by OPC). NB's PHIPAA sits within a small cluster of provincial health-privacy statutes (with Ontario, Nova Scotia, Newfoundland and Labrador) imposing similar mandatory breach-notification duties on health custodians. Accountability (including responsibility for third-party processors) and security-safeguard obligations (Schedule 1, Principle 4.7) are documented. DPO appointment thresholds, formal ROPA requirements, and joint-controller-arrangement rules were not located as distinct statutory features of PIPEDA/RTIPPA/PHIPAA.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA's accountability principle keeps organizations responsible for personal information transferred to a third party for processing. No formal DPIA statutory obligation distinct from this principle.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA's 'breach of security safeguards' definition is defined by reference to loss of, unauthorized access to, or unauthorized disclosure of personal information from a Schedule 1 Principle 4.7 safeguards breach or failure to establish safeguards. Security-safeguards anchor for M4.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA requires reporting to OPC and notifying affected individuals of any breach of security safeguards posing a real risk of significant harm (RROSH). Best-evidenced M4 sub-module; RROSH threshold central to PIPEDA breach regime.observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA breach-duty offence provision penalizes knowing non-compliance with fines of up to $100,000, prosecuted federally rather than administratively imposed by OPC. Materially weaker deterrent than GDPR turnover-based fines; see key_judgments.observed
  5. ConfirmedIAPP — New Brunswick (PHIPAA) imposes, alongside ON/NS/NL, mandatory breach notification/reporting obligations on health-sector custodians. Sub-national health-sector overlay; do not collapse into a single Canada-wide rule.observed
  6. ConfirmedIAPP — PIPEDA requires retention of breach records for two years, available to OPC upon request. Retention duty tied to breach-record-keeping.observed

#

Transfer mechanism, adequacy-received status and NB health-sector localisation rule are evidenced; SCC/BCR, TIA and adequacy-granted sub-modules are gaps because Canada's regime does not operate GDPR-equivalent instruments in these areas.

Primary frameworkPIPEDA (accountability-based transfer regime); EU Commission adequacy decision for Canada (organizations subject to PIPEDA); PHIPAA s.19 (NB, cross-border health-data consent)
Traffic-light rationale — AmberTransfer mechanism, adequacy-received status and NB health-sector localisation rule are evidenced; SCC/BCR, TIA and adequacy-granted sub-modules are gaps because Canada's regime does not operate GDPR-equivalent instruments in these areas.

Sub-modules (6)

Transfer MechanismsGreen

PIPEDA requires contractual/other means to ensure comparable protection when personal information is processed by third parties, domestically or cross-border.

Claims (1):

  • PIPEDA requires contractual/other means to ensure comparable protection when personal information is processed by third-party service providers, domestically or cross-border, including jurisdiction-of-processing provisions. Accountability-based transfer mechanism; no SCC/BCR-equivalent regime.

Adequacy ReceivedAmber

The EU renewed its adequacy decision covering PIPEDA-subject Canadian organizations in January 2024, tied partly to the (since-lapsed) Bill C-27 reform trajectory.

Claims (1):

  • European Commission renewed adequacy decision (January 2024) covering organizations subject to PIPEDA, citing then-pending Bill C-27 reforms as a factor it would continue to monitor. Bill C-27's death (Jan 2025) creates unresolved uncertainty for the EU's next adequacy monitoring cycle; see key_judgments.

Adequacy GrantedRed

No adequacy decisions granted by Canada/NB to other jurisdictions were located in this pass.

Sccs And BcrsRed

PIPEDA does not operate an SCC/BCR-equivalent certification regime; none was located.

Transfer Impact AssessmentRed

No PIPEDA/PHIPAA/RTIPPA transfer-impact-assessment obligation was located in this pass.

Data LocalisationAmber

PHIPAA imposes an express-consent requirement (s.19) for disclosure of personal health information outside New Brunswick.

Claims (1):

  • PHIPAA s.19 requires only express consent for disclosure of personal health information outside New Brunswick. NB-specific consent-based localisation rule for health data.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative96 words

PIPEDA relies on an accountability-based transfer mechanism (contractual/other means providing comparable protection) rather than a GDPR-style SCC/BCR/TIA regime. Canada (via PIPEDA-covered organizations) holds an EU adequacy decision, renewed in January 2024, with the European Commission expressly citing then-pending Bill C-27 reforms as a factor it would continue to monitor (Bill C-27 subsequently died on prorogation in January 2025, creating some uncertainty about future EU monitoring outcomes). NB's PHIPAA imposes an express-consent requirement for cross-border disclosure of personal health information. No SCC/BCR-equivalent instruments, formal transfer-impact-assessment obligation, or outbound adequacy grants from Canada/NB to other regimes were located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA requires contractual/other means to ensure comparable protection when personal information is processed by third-party service providers, domestically or cross-border, including jurisdiction-of-processing provisions. Accountability-based transfer mechanism; no SCC/BCR-equivalent regime.observed
  2. ConfirmedIAPP — European Commission renewed adequacy decision (January 2024) covering organizations subject to PIPEDA, citing then-pending Bill C-27 reforms as a factor it would continue to monitor. Bill C-27's death (Jan 2025) creates unresolved uncertainty for the EU's next adequacy monitoring cycle; see key_judgments.observed
  3. ConfirmedDataGuidance (OneTrust) — PHIPAA s.19 requires only express consent for disclosure of personal health information outside New Brunswick. NB-specific consent-based localisation rule for health data.observed

#

Financial, health, employment, credit and insurance overlays are evidenced; telecoms/ePrivacy and education sub-modules are gaps in this pass.

Primary frameworkPIPEDA plus sectoral overlays: Bank Act (financial); PHIPAA (health); provincial consumer-credit-reporting statutes (credit)
Traffic-light rationale — AmberFinancial, health, employment, credit and insurance overlays are evidenced; telecoms/ePrivacy and education sub-modules are gaps in this pass.

Sub-modules (7)

Financial Sector OverlayAmber

The Bank Act regulates personal financial information handling by federally regulated financial institutions, in parallel with PIPEDA.

Claims (1):

  • Bank Act (federal) regulates personal financial information handling by federally regulated financial institutions, in parallel with PIPEDA. Routed to financial-integrity for AML-adjacent framing; DP retains only the data-protection overlay.

Health Sector OverlayGreen

PHIPAA displaces PIPEDA for NB health information custodians as a substantially similar sectoral law.

Claims (1):

  • PHIPAA governs and is deemed substantially similar to PIPEDA for personal health information held by NB health information custodians, displacing PIPEDA's application to that data. Displacement/substantially-similar-law mechanic, distinct from PIPEDA's default application elsewhere in NB.

Telecoms And EprivacyRed

No telecoms/ePrivacy-specific statute (e.g., CASL) detail was retrieved as part of this research pass.

Employment DataAmber

PIPEDA covers employee/applicant personal information for federally regulated works, undertakings and businesses.

Claims (1):

  • PIPEDA applies to personal information of employees/applicants of federal works, undertakings and businesses (FWUBs). FWUB employment-data coverage.

Credit And ScoringAmber

Provincial consumer-credit-reporting laws impose confidentiality obligations on credit agencies alongside PIPEDA.

Claims (1):

  • Most Canadian provinces (consumer credit reporting laws) impose confidentiality obligations on credit reporting agencies in addition to PIPEDA's general principles. Confidence held at Probable per original research (0.6); NB-specific credit-reporting statute text not independently confirmed.

EducationRed

No NB-specific education-sector statute was retrieved; cross-jurisdictional EdTech privacy guidance is captured under children_and_vulnerable_groups instead.

InsuranceAmber

Insurance companies are treated as PIPEDA-subject organizations for breach-reporting purposes.

Claims (1):

  • Insurance companies operating in Canada are subject to PIPEDA and must report privacy breaches posing a real risk of significant harm. Insurance-sector RROSH applicability.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative84 words

Multiple sector overlays intersect with PIPEDA in NB: the federal Bank Act regulates federally-regulated financial institutions' handling of personal financial information; PHIPAA displaces PIPEDA for NB health custodians; PIPEDA covers FWUB employee/applicant data; provincial consumer-credit-reporting laws impose confidentiality duties on credit agencies; and insurance companies are treated as PIPEDA-subject organizations for RROSH breach-reporting purposes. Telecoms/ePrivacy-specific rules (e.g., Canada's Anti-Spam Legislation) and NB-specific education-sector privacy rules were not directly retrieved in this pass (education is partly addressed via the cross-jurisdictional EdTech resolution captured under children_and_vulnerable_groups).

Sources and claims (5)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — Bank Act (federal) regulates personal financial information handling by federally regulated financial institutions, in parallel with PIPEDA. Routed to financial-integrity for AML-adjacent framing; DP retains only the data-protection overlay.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — PHIPAA governs and is deemed substantially similar to PIPEDA for personal health information held by NB health information custodians, displacing PIPEDA's application to that data. Displacement/substantially-similar-law mechanic, distinct from PIPEDA's default application elsewhere in NB.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA applies to personal information of employees/applicants of federal works, undertakings and businesses (FWUBs). FWUB employment-data coverage.observed
  4. ProbableOffice of the Privacy Commissioner of Canada — Most Canadian provinces (consumer credit reporting laws) impose confidentiality obligations on credit reporting agencies in addition to PIPEDA's general principles. Confidence held at Probable per original research (0.6); NB-specific credit-reporting statute text not independently confirmed.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — Insurance companies operating in Canada are subject to PIPEDA and must report privacy breaches posing a real risk of significant harm. Insurance-sector RROSH applicability.observed

#

Only one of six sub-modules (dark patterns) has direct evidentiary support in this pass.

Traffic-light rationale — RedOnly one of six sub-modules (dark patterns) has direct evidentiary support in this pass.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-consent-specific statute was retrieved in this pass beyond PIPEDA's general consent principles.

Dark PatternsAmber

OPC publishes non-binding guidance on deceptive design patterns affecting personal-information disclosure.

Claims (1):

  • Office of the Privacy Commissioner of Canada (OPC) publishes non-binding guidance on deceptive design patterns ('dark patterns') that may influence individuals into disclosing more personal information online. Only well-evidenced adtech sub-module this cycle; cookies, opt-out signals, clean rooms, cross-context advertising and CASL-based direct marketing all gaps (gdpri-int-3).

Opt Out SignalsRed

No Global-Privacy-Control-equivalent recognition regime was retrieved for Canada/NB.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rules were retrieved.

Cross Context AdvertisingRed

No cross-context-advertising-specific ('sale'/'share') statute was retrieved for Canada/NB.

Direct MarketingRed

Canada's Anti-Spam Legislation (CASL) is the likely relevant instrument for direct-marketing consent/suppression but was not researched in this pass; absent_field_provenance applies.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative35 words

Evidence in this pass is limited to OPC guidance on deceptive design patterns ('dark patterns'). No NB/federal cookie-consent statute, opt-out-signal recognition regime (e.g., GPC), clean-room rules, cross-context-advertising regime, or direct-marketing-specific statute (e.g., CASL) was retrieved.

Sources and claims (1)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — Office of the Privacy Commissioner of Canada (OPC) publishes non-binding guidance on deceptive design patterns ('dark patterns') that may influence individuals into disclosing more personal information online. Only well-evidenced adtech sub-module this cycle; cookies, opt-out signals, clean rooms, cross-context advertising and CASL-based direct marketing all gaps (gdpri-int-3).observed

#

The historical/current non-force status of AIDA and ADM-contest proposals is well evidenced; profiling, genetic-data and surveillance-carveout sub-modules remain gaps.

Traffic-light rationale — AmberThe historical/current non-force status of AIDA and ADM-contest proposals is well evidenced; profiling, genetic-data and surveillance-carveout sub-modules remain gaps.

Sub-modules (6)

Profiling RestrictionsRed

No PIPEDA-specific profiling-restriction provision analogous to GDPR Art 22 was retrieved in this pass.

Automated Decision Making TransparencyAmber

A proposed statutory right to contest automated decisions under the CPPA never came into force after Bill C-27 died on prorogation.

Claims (1):

  • Consumer Privacy Protection Act (proposed, within Bill C-27) proposed but never took effect: statutory right to contest automated decisions; no equivalent binding right currently exists under PIPEDA following Bill C-27's death on prorogation (January 2025). Routed to artificial-intelligence for AI-Act-equivalent framing; DP retains the ADM-transparency/profiling angle.

Ai Risk AssessmentsAmber

The proposed AIDA cross-sector AI risk-assessment framework died with Bill C-27 in January 2025 and has not been reintroduced as of this research pass.

Claims (1):

  • Artificial Intelligence and Data Act (AIDA, within Bill C-27) died along with Bill C-27 upon prorogation January 6, 2025; Canada's proposed cross-sector AI risk-assessment framework is not in force and no successor bill was confirmed as of this pass. Routed to artificial-intelligence; see gdpri-int-6 for successor-bill gap.

Biometric RegimeAmber

OPC publishes non-binding biometrics guidance; no dedicated federal or NB biometric-specific statute was confirmed.

Claims (1):

  • Office of the Privacy Commissioner of Canada (OPC) maintains non-binding guidance on biometrics; no dedicated federal or New Brunswick biometric-specific statute was confirmed in this pass. Absence of dedicated statute is itself the finding; searched two biometric-specific query vectors without result (see original absent_field_provenance).

Genetic DataRed

No NB/federal genetic-data-specific statutory regime was located; the 23andMe genetic-data breach investigation is treated under enforcement_and_redress rather than as a distinct genetic-data statute.

State Surveillance CarveoutsRed

No state-surveillance carve-out provision specific to PIPEDA/RTIPPA/PHIPAA was retrieved in this pass.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative74 words

Canada's principal vehicle for statutory AI/ADM/biometric governance, the Artificial Intelligence and Data Act (AIDA) and the CPPA's proposed ADM-contest right, were both part of Bill C-27, which died when Parliament was prorogued on January 6, 2025; neither is currently in force. The OPC maintains non-binding guidance addressing biometrics generally. Profiling restrictions, genetic-data-specific regime, and state-surveillance carve-outs were not located as distinct provisions in this pass (the 23andMe genetic-data breach investigation is captured under enforcement_and_redress).

Sources and claims (3)
  1. ConfirmedDataGuidance (OneTrust) — Consumer Privacy Protection Act (proposed, within Bill C-27) proposed but never took effect: statutory right to contest automated decisions; no equivalent binding right currently exists under PIPEDA following Bill C-27's death on prorogation (January 2025). Routed to artificial-intelligence for AI-Act-equivalent framing; DP retains the ADM-transparency/profiling angle.observed
  2. ConfirmedDataGuidance (OneTrust) — Artificial Intelligence and Data Act (AIDA, within Bill C-27) died along with Bill C-27 upon prorogation January 6, 2025; Canada's proposed cross-sector AI risk-assessment framework is not in force and no successor bill was confirmed as of this pass. Routed to artificial-intelligence; see gdpri-int-6 for successor-bill gap.observed
  3. UncertainOffice of the Privacy Commissioner of Canada — Office of the Privacy Commissioner of Canada (OPC) maintains non-binding guidance on biometrics; no dedicated federal or New Brunswick biometric-specific statute was confirmed in this pass. Absence of dedicated statute is itself the finding; searched two biometric-specific query vectors without result (see original absent_field_provenance).observed

#

Only the education_settings sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Traffic-light rationale — RedOnly the education_settings sub-module has direct evidentiary support; the remaining four sub-modules are gaps.

Sub-modules (5)

Age VerificationRed

No PIPEDA/RTIPPA/PHIPAA age-verification-specific rule was retrieved.

Minor Profiling BansRed

No minor-specific profiling ban was retrieved under PIPEDA, RTIPPA or PHIPAA.

Education SettingsAmber

A November 2025 FPT joint resolution addresses children's/youth privacy in classroom EdTech use.

Claims (1):

  • Federal, Provincial and Territorial Privacy Commissioners and Ombuds (including New Brunswick) issued a joint resolution (October 2025, corrected from an initial November 2025 research draft) on protecting children's and youth privacy in classroom use of educational technologies. Corrected via Challenger fold f-002: original 'November 2025' date was inconsistent with the same FPT meeting cycle's October 2025 co-chair handover (claim a0000023); resolution dated to the October 2025 Banff, Alberta annual FPT meeting per OPC 2025-2026 Annual Report.

Dependent AdultsRed

No dependent-adult-specific privacy protection was retrieved under PIPEDA, RTIPPA or PHIPAA in this pass.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative59 words

The clearest evidenced development is the November 2025 joint resolution by the federal Privacy Commissioner and provincial/territorial counterparts (including New Brunswick's) on protecting children's and youth privacy in classroom EdTech use; this is a non-binding cooperative resolution rather than a statute. Age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, and dependent-adult protections specific to PIPEDA/RTIPPA/PHIPAA were not retrieved in this pass.

Sources and claims (1)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — Federal, Provincial and Territorial Privacy Commissioners and Ombuds (including New Brunswick) issued a joint resolution (October 2025, corrected from an initial November 2025 research draft) on protecting children's and youth privacy in classroom use of educational technologies. Corrected via Challenger fold f-002: original 'November 2025' date was inconsistent with the same FPT meeting cycle's October 2025 co-chair handover (claim a0000023); resolution dated to the October 2025 Banff, Alberta annual FPT meeting per OPC 2025-2026 Annual Report.observed

#

Regulator powers, penalties, recent enforcement activity, private right of action, and 180-day developments are all well evidenced from primary OPC sources.

Primary frameworkPIPEDA ss.10.1-14 (enforcement, breach offences, Federal Court recourse)
Traffic-light rationale — GreenRegulator powers, penalties, recent enforcement activity, private right of action, and 180-day developments are all well evidenced from primary OPC sources.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

OPC refers possible offences to the Attorney General rather than prosecuting or fining directly; knowing breach-duty violations can draw fines up to $100,000.

Claims (2):

  • Office of the Privacy Commissioner of Canada (OPC) does not itself prosecute or fine under PIPEDA; may refer possible offences to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions. OPC has no direct administrative fining power; complaint/investigation-led model.
  • PIPEDA breach-duty violations (knowing) can result in fines of up to $100,000, prosecuted federally rather than administratively imposed by OPC. Penalty ceiling narrow relative to GDPR turnover-based fines.

Enforcement Activity IndexGreen

2025-2026 activity includes joint 23andMe and TikTok investigations and the PowerSchool breach-measures commitment.

Claims (2):

  • Office of the Privacy Commissioner of Canada (OPC) released findings (2025-2026) of joint investigations into 23andMe (with the UK Information Commissioner) and TikTok (with Quebec, British Columbia and Alberta privacy authorities). Cross-border joint-enforcement pattern; 23andMe carries a genetic-data dimension not treated as a distinct statutory regime (see gdpri-int gaps for M8 genetic_data).
  • PowerSchool committed to strengthened breach measures following engagement with the Privacy Commissioner of Canada. Engagement-driven remediation rather than formal enforcement order.

Regulator Funding And CapacityRed

No specific OPC budget/headcount figures for the 2025-2026 period were retrieved in this pass.

Collective Redress And Class ActionsRed

No PIPEDA/RTIPPA/PHIPAA-specific class-action or collective-redress mechanism was retrieved in this pass (Quebec's Law 25 punitive-damages regime is a different JID and out of scope).

Private Right Of ActionGreen

PIPEDA allows Federal Court damages claims, but only following an OPC investigation and report of findings or discontinuance notice.

Claims (1):

  • PIPEDA provides individuals a right to bring an organization before the Federal Court for damages, but only following an OPC investigation and a report of findings or notice of discontinuance. OPC-gated private right of action; asymmetric relative to some provincial statutory-tort regimes (see gdpri-int-5).

Recent Developments 180DGreen

The 2025-2026 Annual Report was tabled June 4, 2026; Commissioner Dufresne became FPT co-chair in October 2025.

Claims (2):

  • OPC 2025-2026 Annual Report ('Championing privacy in the age of AI') was tabled to Parliament on June 4, 2026, highlighting children's privacy and AI-governance efforts. Lead-signal source for this cycle.
  • Commissioner Philippe Dufresne became co-chair of the Federal, Provincial and Territorial Information and Privacy Commissioners and Ombuds group, alongside the Information Commissioner of Canada. Cross-referenced against claim a000001d (EdTech resolution) for internal date consistency post-fold.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative124 words

Enforcement architecture is well documented: the OPC cannot itself levy fines or prosecute PIPEDA offences, instead referring matters to the Attorney General of Canada, while knowing violations of breach-reporting/notification/record-keeping duties can attract fines up to $100,000 through federal prosecution. Individuals have a limited private right of action to the Federal Court for damages, but only after an OPC investigation and report of findings. Recent enforcement activity includes joint investigations into 23andMe (with the UK ICO) and TikTok (with Quebec, BC and Alberta authorities), and engagement leading PowerSchool to commit to strengthened breach measures, all captured in the OPC's 2025-2026 Annual Report ('Championing privacy in the age of AI'), tabled June 4, 2026. Regulator funding/headcount specifics and collective-redress/class-action mechanisms were not retrieved in this pass.

Periodic update · new data 2026-09-28

Enforcement & Redress

Bill 46, An Act to Amend the Right to Information and Protection of Privacy Act, received Royal Assent in the 58th Legislature, 1st Session, a confirmed legislative development for New Brunswick's public-sector information and privacy regime. The precise commencement date of this amendment was not resolved this cycle, so it is not yet possible to state when its provisions take practical effect. This sits within a public-sector framework where an applicant refused access under RTIPPA already has the right to file a complaint with Ombud NB or to refer the matter to the Court of King's Bench of New Brunswick for review, and where public bodies have, since 2018-04-01, been required by the RTIPPA Regulations to notify affected individuals and the Ombud of certain privacy breaches involving personal information.

Ombud NB submitted input as part of a 2025 legislative review of RTIPPA on 2026-01-28. The outcome of that review, including whether it recommends any expansion of New Brunswick's data-protection jurisdiction to cover the private sector, a jurisdiction currently held entirely by the federal PIPEDA regime, was not resolved this cycle. Taken together, the confirmed Bill 46 Royal Assent and the pending 2025 legislative review outcome are read as an escalating trajectory for this module: New Brunswick's public-sector redress framework is actively under legislative reconsideration.

Outlook

Two concrete items to track: the coming-into-force date of Bill 46's amendments, and the substantive outcome of Ombud NB's 2025 legislative review, particularly any recommendation touching private-sector jurisdiction. Either development would materially change the shape of this module's baseline.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedOffice of the Privacy Commissioner of Canada — Office of the Privacy Commissioner of Canada (OPC) does not itself prosecute or fine under PIPEDA; may refer possible offences to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions. OPC has no direct administrative fining power; complaint/investigation-led model.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA breach-duty violations (knowing) can result in fines of up to $100,000, prosecuted federally rather than administratively imposed by OPC. Penalty ceiling narrow relative to GDPR turnover-based fines.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — Office of the Privacy Commissioner of Canada (OPC) released findings (2025-2026) of joint investigations into 23andMe (with the UK Information Commissioner) and TikTok (with Quebec, British Columbia and Alberta privacy authorities). Cross-border joint-enforcement pattern; 23andMe carries a genetic-data dimension not treated as a distinct statutory regime (see gdpri-int gaps for M8 genetic_data).observed
  4. ConfirmedOffice of the Privacy Commissioner of Canada — PowerSchool committed to strengthened breach measures following engagement with the Privacy Commissioner of Canada. Engagement-driven remediation rather than formal enforcement order.observed
  5. ConfirmedOffice of the Privacy Commissioner of Canada — PIPEDA provides individuals a right to bring an organization before the Federal Court for damages, but only following an OPC investigation and a report of findings or notice of discontinuance. OPC-gated private right of action; asymmetric relative to some provincial statutory-tort regimes (see gdpri-int-5).observed
  6. ConfirmedOffice of the Privacy Commissioner of Canada — OPC 2025-2026 Annual Report ('Championing privacy in the age of AI') was tabled to Parliament on June 4, 2026, highlighting children's privacy and AI-governance efforts. Lead-signal source for this cycle.observed
  7. ConfirmedOffice of the Privacy Commissioner of Canada — Commissioner Philippe Dufresne became co-chair of the Federal, Provincial and Territorial Information and Privacy Commissioners and Ombuds group, alongside the Information Commissioner of Canada. Cross-referenced against claim a000001d (EdTech resolution) for internal date consistency post-fold.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct78.26
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for New Brunswick, Canada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data (partial), controller_processor_duties (breach_notification/security/accountability), cross_border_and_adequacy (transfer_mechanisms/adequacy_received/data_localisation), sectoral_watch (financial/health/employment/credit/insurance), and enforcement_and_redress achieved T1/T2 primary-regulator-sourced coverage (OPC official pages, annual reports, statutory guidance). data_subject_rights (beyond access_right), adtech_and_commercial_privacy (beyond dark_patterns), algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups (beyond education_settings), and several controller_processor_duties/cross_border/sectoral sub-modules (DPO, ROPA, joint-controller, SCC/BCR, TIA, adequacy_granted, telecoms/eprivacy, education) rely on T3 secondary analysis (IAPP, DataGuidance) or carry explicit absent_field_provenance gaps because no NB/federal statutory text was retrieved in this pass.

Unresolved questions (6):

  • What is the exact statutory text of RTIPPA's correction/rectification and response-deadline provisions for NB public bodies?
  • Does PIPEDA or provincial guidance establish a fixed age-of-consent or parental-consent threshold applicable in New Brunswick, or is it purely capacity-based?
  • Does Canada's Anti-Spam Legislation (CASL) impose NB-applicable direct-marketing/cookie-consent obligations not captured via PIPEDA alone?
  • What are current OPC budget and headcount figures for 2025-2026 relevant to regulator_funding_and_capacity?
  • Is there a NB-specific or federal collective-redress/class-action mechanism for privacy claims distinct from Quebec's Law 25 regime?
  • Following the death of Bill C-27 (AIDA/CPPA) in January 2025, has a successor federal privacy/AI reform bill been introduced as of the current reporting date?

Escalate to primary-source review: yes