Not publishable as-is. 3 of 7 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Ontario, Canada
CA-ONschema gdpri-v2trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC
Last updated update date not yet available · 10 categories · 60
claims · 28 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
60Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
No content recorded at this JID path.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Framework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.
Primary frameworkPIPEDA (federal, private sector) + PHIPA/FIPPA/CYFSA Part X (Ontario sectoral/public sector)
Traffic-light rationale — AmberFramework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.
Sub-modules (5)
Regulator And AuthorityGreen
OPC (federal, Gatineau HQ with a Toronto regional office) enforces PIPEDA; IPC Ontario enforces PHIPA/FIPPA/CYFSA Part X. The two regulators operate under a 2025-updated MOU enabling joint investigations.
Claims (2):
The Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.
The Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').
PIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.
Material ScopeGreen
PIPEDA covers factual or subjective recorded/unrecorded information about an identifiable individual collected in commercial activity.
Claims (1):
Under PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.
Territorial ScopeGreen
PIPEDA applies to interprovincial/international transfers and to organizations doing business in/into Canada regardless of headquarters location, as confirmed by Federal Court/FCA rulings on Google's search service.
Claims (1):
The Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.
Regulator Registration And FilingAmber
PIPEDA imposes no general registration/filing regime on controllers; the only affirmative filing-adjacent duty is mandatory breach record-keeping (2-year retention, producible to OPC on request).
PIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.
Category narrative80 words
CA-ON sits inside Canada's federated privacy architecture: the federal Office of the Privacy Commissioner of Canada (OPC) enforces PIPEDA as the general private-sector omnibus statute across Ontario (no substantially-similar provincial private-sector law exists in Ontario, unlike AB/BC/QC), while the Ontario Information and Privacy Commissioner (IPC) enforces three Ontario-specific sectoral/public statutes: PHIPA (health), FIPPA (provincial public sector access/privacy) and Part X of the CYFSA (child welfare privacy). This creates a dual-regulator, sector-stacked model rather than a single comprehensive Ontario private-sector statute.
Sources and claims (6)
ConfirmedOPC — The Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.observed
ConfirmedOPC — The Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').observed
ConfirmedOPC — PIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.observed
ConfirmedOPC — Under PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.observed
ConfirmedOPC — The Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.observed
ConfirmedIAPP — PIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.observed
Consent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.
Traffic-light rationale — AmberConsent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.
Sub-modules (4)
Lawful BasesAmber
Consent is essentially the sole lawful basis for collection, use and disclosure of personal information under PIPEDA, unlike the GDPR's multiple legal bases (contract, legitimate interest, etc.).
Claims (1):
Consent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.
Consent ThresholdsGreen
Valid consent under s.6.1 requires that it be reasonable to expect the individual would understand the nature, purpose and consequences of the collection, use or disclosure; several statutory no-consent exceptions exist (fraud detection, breach investigation).
Claims (2):
Section 6.1 of PIPEDA provides that consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.
Since the 2015 Digital Privacy Act amendments, organizations may disclose personal information without consent to investigate a breach of agreement/law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.
Special CategoriesAmber
PIPEDA has no codified list of special/sensitive categories; sensitivity is assessed contextually under Schedule 1. PHIPA creates Ontario's distinct statutory regime for personal health information handled by health information custodians.
Claims (1):
The IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.
Pseudonymisation And AnonymisationAmber
No statutory anonymization/de-identification safe-harbour exists in PIPEDA; the Commissioner recommended strengthening the deidentification/anonymization framework as part of stalled federal reform, while IPC Ontario has issued its own updated structured-data de-identification guidelines.
Claims (2):
The Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.
The IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.
Category narrative67 words
PIPEDA is a consent-centric regime: unlike the GDPR's multiple lawful bases, consent (express or implied, calibrated to sensitivity) is the near-exclusive gateway to collection, use and disclosure, subject to a defined list of statutory exceptions. There is no GDPR Art.9-style enumerated 'special category' regime, though PHIPA creates a distinct high-sensitivity regime for personal health information in Ontario, and CYFSA gives children in provincial care specific privacy rights.
Sources and claims (6)
ConfirmedIAPP — Consent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.observed
ConfirmedOPC — Section 6.1 of PIPEDA provides that consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.observed
ConfirmedOPC — Since the 2015 Digital Privacy Act amendments, organizations may disclose personal information without consent to investigate a breach of agreement/law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.observed
ConfirmedOneTrust DataGuidance — The IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.observed
ProbableIAPP — The Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.observed
ProbableOneTrust DataGuidance — The IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.observed
Core access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.
Traffic-light rationale — AmberCore access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.
Sub-modules (5)
Access RightGreen
PIPEDA Principle 4.9.4 requires organizations to respond to individual access requests within a reasonable time frame and at minimal or no cost.
Claims (1):
Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.
Rectification And ErasureAmber
PIPEDA's 'challenging compliance' principle allows individuals to dispute accuracy, but the OPC/Federal Court found no extension of accuracy obligations to underlying linked article content, leaving broad erasure/de-indexing rights unresolved.
Claims (1):
After investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.
Restriction And ObjectionRed
No explicit statutory restriction-of-processing or objection-to-profiling right exists under PIPEDA in force today.
Absence provenance: unavailable. Searched: PIPEDA right to restrict processing, PIPEDA right to object profiling.
Data PortabilityAmber
Bill C-15 proposes a new Division 1.2 in PIPEDA requiring an organization, on request, to disclose an individual's collected personal information to a designated organization under a data-mobility framework — not yet in force.
Claims (1):
Bill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.
Deadlines And Response WindowsAmber
Access requests must be answered within a reasonable time and at minimal or no cost under Principle 4.9.4; no fixed statutory day-count deadline (e.g., 30 days) was identified for PIPEDA generally.
Claims (1):
Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.
Category narrative77 words
PIPEDA provides an access right and a 'challenging compliance' right functioning as an implicit correction mechanism, with a 'reasonable time and minimal/no cost' response standard (Principle 4.9.4). There is no explicit statutory restriction/objection right or portability right in force; a right to data mobility is only now being proposed via Bill C-15 amendments to PIPEDA. De-indexing/erasure remains contested — the OPC/Federal Court found Google's accuracy obligations do not extend to underlying linked content, leaving right-to-be-forgotten scope unresolved.
Sources and claims (3)
ConfirmedOPC — Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.observed
ConfirmedOPC — After investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.observed
ProbableOPC — Bill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.observed
Breach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).
Traffic-light rationale — AmberBreach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).
Sub-modules (7)
Accountability And DpiaAmber
PIPEDA's accountability principle makes an organization responsible for personal information transferred to a processor; no statutory DPIA obligation exists, though the Commissioner has recommended one for high-risk activities in stalled reform.
Claims (2):
PIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.
The Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.
Dpo RequirementsAmber
PIPEDA contains no statutory DPO-appointment threshold analogous to GDPR Art.37; Schedule 1 requires designation of an accountable individual but not a formal statutory office.
No general records-of-processing-activities obligation exists in PIPEDA; the closest analogue is the mandatory breach record-keeping duty covering all breaches regardless of harm level, retained for two years.
Claims (1):
PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.
Joint Controller ArrangementsAmber
PIPEDA treats the 'principal organization' (in control of the data) as responsible for breach reporting even where the breach occurs at a third-party processor, rather than imposing joint/several notification duties on both parties.
Claims (1):
The OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.
Security MeasuresGreen
Principle 4.7 requires that personal information be protected by security safeguards appropriate to the sensitivity of the information.
Claims (1):
Principle 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.
Breach NotificationAmber
Organizations must report to the OPC and notify affected individuals of breaches posing a 'real risk of significant harm'; the timeline standard is criticized as vague and the Commissioner has recommended a fixed 7-day reporting requirement.
Claims (3):
Organizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.
Significant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.
PIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.
Retention And DisposalAmber
Breach records must be retained for two years and produced to the OPC upon request; no general retention-limit statute for all personal information was located.
Claims (1):
PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.
Category narrative90 words
Accountability is a foundational PIPEDA principle: organizations remain responsible for personal information transferred to third-party processors and must ensure comparable protection contractually. Statutory DPIA and DPO-appointment thresholds (GDPR Art.35/37 analogues) are absent from PIPEDA; the Commissioner has recommended a PIA requirement for high-risk processing as part of stalled reform. Breach notification is mandatory where a 'real risk of significant harm' exists, but the timeline standard ('as soon as feasible') is criticized as vague, and the OPC lacks direct fining power for breach-reporting failures (referral to the Attorney General is required).
Sources and claims (8)
ConfirmedOPC — PIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.observed
ProbableIAPP — The Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.observed
ConfirmedIAPP — PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.observed
ConfirmedOPC — The OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.observed
ConfirmedOPC — Principle 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.observed
ConfirmedOPC — Organizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.observed
ConfirmedOPC — Significant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.observed
ProbableOPC — PIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.observed
Adequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.
Primary frameworkPIPEDA (no dedicated transfer chapter) + EU Commission Decision 2002/2/EC as reviewed 2024
Traffic-light rationale — AmberAdequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.
Sub-modules (6)
Transfer MechanismsAmber
PIPEDA does not contain separate and explicit rules governing trans-border data flows; instead it requires transparency about foreign processing and requires organizations to ensure a comparable level of protection via contractual or other means for third-party processing.
Claims (2):
PIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.
PIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.
Adequacy ReceivedGreen
Not applicable in the outbound sense for CA-ON as a receiving jurisdiction from the EU; see adequacy_granted for Canada's inbound adequacy from the EU.
Adequacy GrantedGreen
The European Commission concluded in January 2024 that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA, as part of an 11-jurisdiction periodic adequacy review; the UK separately maintains its own adequacy regulations covering PIPEDA-subject recipients.
Claims (3):
On January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.
Canada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.
Canada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.
Sccs And BcrsAmber
PIPEDA has no dedicated SCC/BCR statutory mechanism; where adequacy does not apply (e.g., non-federally-regulated employee data or intra-provincial data outside PIPEDA's ambit), practitioners rely on contractual safeguards akin to SCCs, and the OPC is exploring the Global CBPR Forum as a further certification-based mechanism.
Claims (2):
The Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.
The Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.
Transfer Impact AssessmentAmber
No statutory TIA requirement equivalent to Schrems II practice was identified as a formal PIPEDA obligation; risk-assessment practice is industry-guidance-driven rather than legislated.
Absence provenance: unavailable. Searched: PIPEDA transfer impact assessment requirement, OPC TIA guidance PIPEDA.
Data LocalisationGreen
No general data-localisation mandate was identified under PIPEDA or Ontario's sectoral statutes.
Absence provenance: unavailable. Searched: PIPEDA data localisation requirement, Ontario PHIPA data residency requirement.
Category narrative87 words
PIPEDA contains no separate explicit trans-border data flow rules; instead it relies on transparency and accountability obligations requiring comparable protection when data is transferred abroad for processing. Canada (for PIPEDA-covered commercial operators) holds a long-standing EU adequacy decision, most recently reconfirmed in the Commission's January 2024 periodic review, with the next review expected around 2028; the UK separately recognizes PIPEDA-covered transfers via its own adequacy regulations. Adequacy is partial: it excludes the substantially-similar provincial regimes of Alberta, British Columbia and Quebec, and generally excludes non-federally-regulated employee data.
Sources and claims (7)
ConfirmedOPC — PIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.observed
ConfirmedOPC — PIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.observed
ConfirmedEUR-Lex — On January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.observed
ProbableOPC — Canada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.observed
ConfirmedIAPP — Canada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.observed
ProbableOPC — The Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.observed
ProbableOPC — The Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.observed
Health sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.
Traffic-light rationale — AmberHealth sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.
Sub-modules (7)
Financial Sector OverlayAmber
Federally-regulated banks are directly subject to PIPEDA as federal works, undertakings or businesses (FWUBs); no distinct Ontario provincial financial-sector privacy overlay was identified.
Claims (1):
Federally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.
Health Sector OverlayGreen
PHIPA governs personal health information handled by Ontario health information custodians, administered by the IPC, and has been declared substantially similar to PIPEDA for health information purposes; the IPC has now issued its first monetary penalties under PHIPA.
Claims (2):
The Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.
The IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.
Telecoms And EprivacyGreen
CASL, the federal anti-spam law, is jointly enforced by the CRTC, OPC and Competition Bureau and separately amended PIPEDA regarding electronic address harvesting.
Claims (1):
At the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.
Employment DataRed
There is currently no privacy legislation applicable to non-federally-regulated Ontario employees; PIPEDA only covers employees/applicants of federally-regulated employers (FWUBs), a gap FPT Commissioners have formally flagged.
Claims (2):
There is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.
Canada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.
Credit And ScoringRed
No distinct Ontario or federal credit-scoring-specific data protection statute was located in this research pass.
Ontario schools/universities are generally covered by provincial (FIPPA/MFIPPA) rather than PIPEDA rules, and Canadian privacy regulators have jointly resolved to strengthen children's privacy protections in EdTech.
Claims (2):
Municipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.
Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.
InsuranceRed
No distinct Ontario or federal insurance-sector data protection overlay was located in this research pass; general PIPEDA/PHIPA rules would apply by default.
Ontario's sectoral overlays are concentrated in health (PHIPA, with a mature IPC administrative-monetary-penalty regime now in active use) and public-sector/child-welfare (FIPPA, CYFSA), while general private-sector employment privacy remains a documented statutory gap outside AB/BC/QC — non-federally-regulated Ontario employees have no dedicated statutory privacy protection distinct from PIPEDA, which itself only covers federally-regulated employers' employees/applicants. Telecoms/e-marketing is separately regulated federally via CASL (CRTC/OPC/Competition Bureau shared enforcement). No distinct Ontario/federal statutory regime for credit-scoring or insurance-sector data was located in this research pass.
Sources and claims (8)
ConfirmedOPC — Federally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.observed
ConfirmedOneTrust DataGuidance — The Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.observed
ConfirmedOneTrust DataGuidance — The IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.observed
ConfirmedOPC — At the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.observed
ConfirmedOPC — There is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.observed
ConfirmedOPC — Canada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.observed
ConfirmedOPC — Municipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.observed
ProbableOneTrust DataGuidance — Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.observed
Direct marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.
Traffic-light rationale — AmberDirect marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.
Sub-modules (6)
Cookies And TrackersAmber
No CA-ON-specific cookie-consent statute (ePrivacy-style) was located; general PIPEDA consent principles apply to tracking technologies by default.
The OPC provides guidance on deceptive design patterns that may influence individuals into giving away more personal information online, though this is guidance rather than a standalone dark-patterns statute.
Claims (1):
The OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.
Opt Out SignalsRed
No statutory recognition of browser-based opt-out signals (e.g., Global Privacy Control) was located under PIPEDA or Ontario statutes.
Absence provenance: unavailable. Searched: PIPEDA Global Privacy Control recognition, Ontario opt-out signal law.
Clean Rooms And DcrRed
No Canadian federal or Ontario-specific clean-room/data-collaboration-room regulatory framework was located.
Absence provenance: unavailable. Searched: Canada data clean room regulation, PIPEDA data collaboration room rules.
Cross Context AdvertisingAmber
PIPEDA has no CPRA-style 'sale'/'share' distinction for cross-context advertising; consent-based rules apply generally to disclosure for advertising purposes.
Absence provenance: unavailable. Searched: PIPEDA cross-context advertising rules, Canada sale of personal information advertising rules.
Direct MarketingGreen
CASL requires express or implied consent, sender identification and unsubscribe mechanisms for commercial electronic messages; implied consent based on an existing business relationship expires after two years; PIPEDA separately prohibits address harvesting with very limited exceptions.
Claims (3):
CASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.
Implied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.
With very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.
Category narrative84 words
Direct marketing/commercial electronic messaging is governed federally by CASL (jointly enforced by CRTC, OPC and Competition Bureau) requiring express or implied consent, sender identification and functioning unsubscribe mechanisms; implied consent from an 'existing business relationship' expires after two years. PIPEDA separately prohibits address harvesting. CRTC enforcement precedent (CompuFinder, $1.1M AMP) demonstrates meaningful sectoral penalty capacity despite PIPEDA itself lacking fining power. No dedicated statutory framework for opt-out signals (e.g., Global Privacy Control), clean rooms/data-collaboration rooms, or cross-context-advertising 'sale/share' concepts (CPRA-style) was located for CA-ON.
Sources and claims (4)
ConfirmedOPC — The OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.observed
ConfirmedIAPP — CASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.observed
ConfirmedIAPP — Implied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.observed
ConfirmedOPC — With very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.observed
No comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.
Primary frameworkNone in force (AIDA/CPPA died with Bill C-27, 2025) — governed ad hoc via PIPEDA general principles and IPC/OPC guidance
Traffic-light rationale — RedNo comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.
Sub-modules (6)
Profiling RestrictionsRed
No statutory Art.22-style profiling restriction is in force in Canada; the stalled CPPA would have introduced algorithmic transparency provisions.
Claims (1):
The CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.
Automated Decision Making TransparencyRed
The proposed (now-stalled) CPPA would have provided algorithmic transparency and a right of individuals to obtain an explanation of automated decisions; this is not currently in force.
Claims (1):
PIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.
Ai Risk AssessmentsRed
AIDA, Canada's first attempt at cross-sector AI risk-assessment legislation for high-impact systems, died with Bill C-27's failure to pass before Parliament's January 2025 prorogation and has not been reintroduced.
Claims (2):
The prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.
As of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.
Biometric RegimeAmber
The OPC is finalizing guidance on biometrics for public and private sector organizations following a fall 2023/winter 2024 public consultation; no standalone biometric statute exists.
Claims (1):
The OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.
Genetic DataAmber
No standalone genetic-data statute was located; the IPC has published 12 guardrails specifically for police use of investigative genetic genealogy, addressing privacy and human-rights concerns.
Claims (1):
Ontario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.
State Surveillance CarveoutsAmber
Detailed evidence on national-security carve-outs specific to CA-ON was not located in this research pass; general federal Privacy Act national-security exemptions are understood to exist but require further primary-source verification.
Absence provenance: unavailable. Searched: Canada national security privacy exemption Ontario, PIPEDA law enforcement disclosure exemption scope.
Category narrative104 words
Canada currently has no comprehensive federal AI statute in force: the Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died when Parliament was prorogued on January 6, 2025, and has not been reintroduced as of this research pass. Algorithmic-transparency/ADM-explanation rights were only proposed (via the stalled CPPA) and are not currently in force. The OPC is finalizing biometrics guidance following a 2023-2024 consultation, and Ontario's IPC has been highly active on AI/biometric governance specifically — co-issuing AI-use principles with the Ontario Human Rights Commission, publishing 12 guardrails for police use of investigative genetic genealogy, and joining a multi-provincial investigation into OpenAI's ChatGPT.
Sources and claims (6)
ProbableIAPP — The CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.observed
ProbableIAPP — PIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.observed
ConfirmedOneTrust DataGuidance — The prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.observed
ProbableIAPP — As of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.observed
ProbableOPC — The OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.observed
ProbableOneTrust DataGuidance — Ontario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.observed
A concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.
Primary frameworkCYFSA Part X (children in care) + PIPEDA general consent principles
Traffic-light rationale — AmberA concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.
Sub-modules (5)
Age VerificationRed
No statutory age-verification threshold was located for CA-ON; PIPEDA applies contextual consent standards rather than a fixed age threshold.
Absence provenance: unavailable. Searched: PIPEDA age of consent minors, Ontario age verification statute.
Parental ConsentRed
No COPPA/GDPR-Art.8-style parental-consent mechanism specific to CA-ON was located; PIPEDA's general 'meaningful consent' standard applies contextually where a minor is involved.
No statutory minor-specific profiling ban was located; the stalled CPPA reform was criticized by commentators for not going far enough on protecting children's/youth privacy.
Claims (1):
Commentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.
Education SettingsAmber
Canadian federal/provincial/territorial privacy commissioners issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.
Claims (1):
Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.
Dependent AdultsRed
No dependent-adult-specific privacy protection regime was located for CA-ON in this research pass.
Ontario's most direct statutory protection for a vulnerable group is Part X of the CYFSA, which gives children in the child-welfare system a right to reasonable privacy and possession of personal property. Federal/provincial commissioners have jointly targeted children's privacy in EdTech and flagged that stalled federal reform (CPPA) did not go far enough on children's/youth privacy. No age-verification or COPPA/GDPR-Art.8-style parental-consent threshold statute was located for CA-ON in this research pass; dependent-adult-specific protections were similarly not identified.
Sources and claims (2)
ProbableIAPP — Commentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.observed
ProbableOneTrust DataGuidance — Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.observed
Ontario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.
Traffic-light rationale — AmberOntario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The OPC cannot prosecute PIPEDA offences or issue fines directly, but can refer possible offences to the Attorney General for prosecution by the Director of Public Prosecutions; the IPC, by contrast, has direct AMP power under PHIPA up to CAD 500,000 for organizations.
Claims (3):
The OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.
The time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.
Following amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.
Enforcement Activity IndexAmber
The OPC closed 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26 amid a significant rise in complaint volumes; the IPC issued its first-ever PHIPA monetary penalties in the same period.
Claims (2):
The OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.
The OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.
Regulator Funding And CapacityAmber
The Commissioner has stressed the need for stable, permanent OPC funding to keep pace with growing complexity of privacy issues, having previously operated on temporary funding.
Claims (1):
The Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.
Collective Redress And Class ActionsAmber
No dedicated statutory class-action mechanism specific to PIPEDA/PHIPA was independently confirmed in this pass; case law (e.g., Hopkins v. Kay) has permitted individual civil suits for PHIPA breaches, suggesting a common-law avenue exists alongside statutory complaint processes.
Claims (1):
In Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.
Private Right Of ActionAmber
CASL originally contemplated a private right of action for contraventions, planned to come into force in a later implementation phase; current operative status requires primary-source confirmation.
Absence provenance: unavailable. Searched: CASL private right of action current status 2026.
Claims (1):
CASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).
Recent Developments 180DGreen
Within the last ~180 days: Commissioner Dufresne testified on Bill C-15's PIPEDA data-mobility amendments before House INDU (Jan 2026) and Senate committees; the OPC/Quebec/BC/Alberta joint OpenAI ChatGPT investigation concluded (May 2026); Dufresne was elected Chair of the Global Privacy Assembly; and the OPC-IPC MOU continues to enable cross-statute joint investigations.
Claims (3):
In January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.
The Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.
Commissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.
Category narrative122 words
Enforcement is bifurcated: the federal OPC operates largely as an ombudsman under PIPEDA with no direct order-making or fining power — it can investigate, issue findings, refer offences to the Attorney General for prosecution, or seek a Federal Court order (application window extended from 45 days to one year) — while Ontario's IPC has direct administrative-monetary-penalty power under PHIPA (up to CAD 500,000 for organizations) and has now used it for the first time. The OPC saw a significant rise in complaint volumes in FY2025-26. Recent developments (within ~180 days) include Bill C-15's proposed PIPEDA data-mobility amendments (Commissioner testimony January-February 2026), the concluded joint OPC/Quebec/BC/Alberta investigation into OpenAI's ChatGPT (May 2026), and the Commissioner's election as Chair of the Global Privacy Assembly.
Sources and claims (11)
ConfirmedOPC — The OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.observed
ConfirmedOPC — The time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.observed
ConfirmedOneTrust DataGuidance — Following amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.observed
ConfirmedOPC — The OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.observed
ConfirmedOPC — The OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.observed
ProbableIAPP — The Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.observed
ProbableOneTrust DataGuidance — In Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.observed
UncertainIAPP — CASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).observed
ConfirmedOPC — In January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.observed
ConfirmedOPC — The Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.observed
ConfirmedOPC — Commissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 3 failing check(s).
schema_valid
pass
min_architecture_patterns
0
min_red_flags
0
min_controls
0
worked_examples_count
0
decision_tree_nodes
0
counterparty_diligence_questions
0
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
board_briefing_present
FAIL
every_practical_object_has_source_id
FAIL
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Ontario, Canada
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 60 claim(s) (61 category placement(s)), 28 source(s) in the cumulative register.
Audit trail
Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.
All 10 modules populated with T1 (priv.gc.ca, EUR-Lex Commission decisions, DataGuidance-sourced primary statute citations) and T3 (IAPP/DataGuidance secondary analysis) sourcing. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, sectoral_watch (health), adtech_and_commercial_privacy (direct marketing), enforcement_and_redress, and recent_developments_180d modules rest on strong T1 primary-source grounding (OPC/IPC official pages, EU Commission adequacy review). algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups modules rest more heavily on T3 secondary reporting (IAPP) given the absence of any current in-force federal AI or children's-privacy statute post-AIDA's death; several sub-modules (credit_and_scoring, insurance, opt_out_signals, clean_rooms_and_dcr, age_verification, parental_consent, dependent_adults, state_surveillance_carveouts) carry explicit absent_field_provenance because no CA-ON-specific statutory source was located despite targeted searches.
Unresolved questions (5):
Current in-force/suspended status of CASL's private right of action provision as of 2026 requires primary-source (Industry Canada / ISED) confirmation.
Whether Bill C-15's data-mobility provisions have progressed beyond committee testimony toward Royal Assent since February 2026.
Whether a successor bill to the dead AIDA/CPPA has been formally tabled in the current (45th) Parliament.
Precise scope of national-security/law-enforcement carve-outs under PIPEDA s.7(3) as applied in Ontario was not independently verified against primary statutory text in this pass.
Whether Ontario has any credit-scoring or insurance-sector-specific privacy overlay not surfaced by this research pass.