🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CA-ON v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 3 failing29 sources retrieved model claude-sonnet-5 · 2026-08-05

Ontario, Canada

CA-ON schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated update date not yet available · 10 categories · 60 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
60Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Framework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.

Primary frameworkPIPEDA (federal, private sector) + PHIPA/FIPPA/CYFSA Part X (Ontario sectoral/public sector)
Traffic-light rationale — AmberFramework is mature and well-documented but structurally fragmented across two regulators and multiple statutes with no unified Ontario private-sector code; federal reform (PIPEDA modernization) remains incomplete.

Sub-modules (5)

Regulator And AuthorityGreen

OPC (federal, Gatineau HQ with a Toronto regional office) enforces PIPEDA; IPC Ontario enforces PHIPA/FIPPA/CYFSA Part X. The two regulators operate under a 2025-updated MOU enabling joint investigations.

Claims (2):

  • The Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.
  • The Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').

Act And InstrumentsGreen

Core instruments: PIPEDA (Royal Assent 2000-04-13); PHIPA 2004; FIPPA R.S.O. 1990; CYFSA 2017 Part X.

Claims (1):

  • PIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.

Material ScopeGreen

PIPEDA covers factual or subjective recorded/unrecorded information about an identifiable individual collected in commercial activity.

Claims (1):

  • Under PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.

Territorial ScopeGreen

PIPEDA applies to interprovincial/international transfers and to organizations doing business in/into Canada regardless of headquarters location, as confirmed by Federal Court/FCA rulings on Google's search service.

Claims (1):

  • The Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.

Regulator Registration And FilingAmber

PIPEDA imposes no general registration/filing regime on controllers; the only affirmative filing-adjacent duty is mandatory breach record-keeping (2-year retention, producible to OPC on request).

Absence provenance: unavailable. Searched: PIPEDA controller registration requirement, Ontario PHIPA registration filing obligation.

Claims (1):

  • PIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.
Category narrative80 words

CA-ON sits inside Canada's federated privacy architecture: the federal Office of the Privacy Commissioner of Canada (OPC) enforces PIPEDA as the general private-sector omnibus statute across Ontario (no substantially-similar provincial private-sector law exists in Ontario, unlike AB/BC/QC), while the Ontario Information and Privacy Commissioner (IPC) enforces three Ontario-specific sectoral/public statutes: PHIPA (health), FIPPA (provincial public sector access/privacy) and Part X of the CYFSA (child welfare privacy). This creates a dual-regulator, sector-stacked model rather than a single comprehensive Ontario private-sector statute.

Sources and claims (6)
  1. ConfirmedOPC — The Office of the Privacy Commissioner of Canada oversees compliance with PIPEDA, Canada's federal private-sector privacy law, and maintains a Toronto regional office to promote PIPEDA compliance in Ontario.observed
  2. ConfirmedOPC — The Information and Privacy Commissioner of Ontario has oversight of personal information and personal health information under FIPPA, PHIPA, and Part X of the CYFSA (the 'Ontario Statutes').observed
  3. ConfirmedOPC — PIPEDA is the complete version that received Royal Assent on April 13, 2000, and Schedule 1 contains the 10 fair information principles referred to throughout the Act.observed
  4. ConfirmedOPC — Under PIPEDA, personal information includes any factual or subjective information, recorded or not, about an identifiable individual, collected in the course of commercial activity.observed
  5. ConfirmedOPC — The Federal Court (2021) and Federal Court of Appeal (2023) confirmed PIPEDA applies to Google's search engine service, establishing that PIPEDA's application is not limited by an organization's foreign incorporation where it collects, uses, or discloses personal information in the course of commercial activities connected to Canada.observed
  6. ConfirmedIAPP — PIPEDA requires organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control, regardless of harm level, for at least two years.observed

#

Consent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.

Primary frameworkPIPEDA Schedule 1 (Fair Information Principles) + PHIPA (health data)
Traffic-light rationale — AmberConsent framework is well-established and judicially tested, but the absence of a codified special-categories list and of a statutory anonymization safe-harbour (features recommended by the Commissioner for the stalled CPPA reform) leaves gaps relative to GDPR-equivalent regimes.

Sub-modules (4)

Lawful BasesAmber

Consent is essentially the sole lawful basis for collection, use and disclosure of personal information under PIPEDA, unlike the GDPR's multiple legal bases (contract, legitimate interest, etc.).

Claims (1):

  • Consent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.

Special CategoriesAmber

PIPEDA has no codified list of special/sensitive categories; sensitivity is assessed contextually under Schedule 1. PHIPA creates Ontario's distinct statutory regime for personal health information handled by health information custodians.

Claims (1):

  • The IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.

Pseudonymisation And AnonymisationAmber

No statutory anonymization/de-identification safe-harbour exists in PIPEDA; the Commissioner recommended strengthening the deidentification/anonymization framework as part of stalled federal reform, while IPC Ontario has issued its own updated structured-data de-identification guidelines.

Claims (2):

  • The Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.
  • The IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.
Category narrative67 words

PIPEDA is a consent-centric regime: unlike the GDPR's multiple lawful bases, consent (express or implied, calibrated to sensitivity) is the near-exclusive gateway to collection, use and disclosure, subject to a defined list of statutory exceptions. There is no GDPR Art.9-style enumerated 'special category' regime, though PHIPA creates a distinct high-sensitivity regime for personal health information in Ontario, and CYFSA gives children in provincial care specific privacy rights.

Sources and claims (6)
  1. ConfirmedIAPP — Consent is a central feature of PIPEDA; subject to limited exceptions, an individual's consent is a necessary condition to the collection, use and disclosure of personal information, unlike the GDPR which permits other bases such as contract performance or legitimate interests.observed
  2. ConfirmedOPC — Section 6.1 of PIPEDA provides that consent is only valid if it is reasonable to expect that an individual to whom the organization's activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.observed
  3. ConfirmedOPC — Since the 2015 Digital Privacy Act amendments, organizations may disclose personal information without consent to investigate a breach of agreement/law, or to detect, suppress or prevent fraud, where seeking consent would compromise the investigation.observed
  4. ConfirmedOneTrust DataGuidance — The IPC is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which creates a distinct sensitive-data regime for personal health information in Ontario.observed
  5. ProbableIAPP — The Commissioner recommended strengthening the CPPA's deidentification and anonymization framework, including requiring that the risk of re-identification be a factor in determining required measures for deidentified data.observed
  6. ProbableOneTrust DataGuidance — The IPC released updated guidelines to help organizations de-identify structured data while safeguarding privacy.observed

#

Core access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.

Primary frameworkPIPEDA Schedule 1 (Principles 4.9-4.9.4) + proposed Bill C-15 data-mobility provisions
Traffic-light rationale — AmberCore access/correction rights exist and are enforced, but portability, explicit restriction/objection, and erasure/de-indexing rights are either absent or only proposed, not yet in force.

Sub-modules (5)

Access RightGreen

PIPEDA Principle 4.9.4 requires organizations to respond to individual access requests within a reasonable time frame and at minimal or no cost.

Claims (1):

  • Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.

Rectification And ErasureAmber

PIPEDA's 'challenging compliance' principle allows individuals to dispute accuracy, but the OPC/Federal Court found no extension of accuracy obligations to underlying linked article content, leaving broad erasure/de-indexing rights unresolved.

Claims (1):

  • After investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.

Restriction And ObjectionRed

No explicit statutory restriction-of-processing or objection-to-profiling right exists under PIPEDA in force today.

Absence provenance: unavailable. Searched: PIPEDA right to restrict processing, PIPEDA right to object profiling.

Data PortabilityAmber

Bill C-15 proposes a new Division 1.2 in PIPEDA requiring an organization, on request, to disclose an individual's collected personal information to a designated organization under a data-mobility framework — not yet in force.

Claims (1):

  • Bill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.

Deadlines And Response WindowsAmber

Access requests must be answered within a reasonable time and at minimal or no cost under Principle 4.9.4; no fixed statutory day-count deadline (e.g., 30 days) was identified for PIPEDA generally.

Claims (1):

  • Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.
Category narrative77 words

PIPEDA provides an access right and a 'challenging compliance' right functioning as an implicit correction mechanism, with a 'reasonable time and minimal/no cost' response standard (Principle 4.9.4). There is no explicit statutory restriction/objection right or portability right in force; a right to data mobility is only now being proposed via Bill C-15 amendments to PIPEDA. De-indexing/erasure remains contested — the OPC/Federal Court found Google's accuracy obligations do not extend to underlying linked content, leaving right-to-be-forgotten scope unresolved.

Sources and claims (3)
  1. ConfirmedOPC — Principle 4.9.4 of PIPEDA Schedule 1 requires an organization to respond to an individual's request for access to personal information within a reasonable time frame and at minimal or no cost to the individual.observed
  2. ConfirmedOPC — After investigating a complaint, the OPC found that Google's accuracy-related obligations under PIPEDA do not extend to the underlying content of linked articles, leaving the scope of any de-indexing/erasure right unsettled at the federal level.observed
  3. ProbableOPC — Bill C-15 would add a new Division 1.2 to PIPEDA requiring an organization, upon an individual's request, to disclose personal information collected from them to a designated organization under a data-mobility framework, subject to regulations.observed

#

Breach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).

Primary frameworkPIPEDA Schedule 1 (Accountability, Safeguards) + Breach of Security Safeguards Regulations (2018)
Traffic-light rationale — AmberBreach notification and accountability duties are in force and judicially reinforced, but DPIA/DPO/ROPA equivalents remain non-statutory, and enforcement of breach obligations is indirect (referral-based, no OPC fining power).

Sub-modules (7)

Accountability And DpiaAmber

PIPEDA's accountability principle makes an organization responsible for personal information transferred to a processor; no statutory DPIA obligation exists, though the Commissioner has recommended one for high-risk activities in stalled reform.

Claims (2):

  • PIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.
  • The Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.

Dpo RequirementsAmber

PIPEDA contains no statutory DPO-appointment threshold analogous to GDPR Art.37; Schedule 1 requires designation of an accountable individual but not a formal statutory office.

Absence provenance: unavailable. Searched: PIPEDA DPO appointment threshold, PHIPA privacy officer requirement.

Ropa RequirementsAmber

No general records-of-processing-activities obligation exists in PIPEDA; the closest analogue is the mandatory breach record-keeping duty covering all breaches regardless of harm level, retained for two years.

Claims (1):

  • PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.

Joint Controller ArrangementsAmber

PIPEDA treats the 'principal organization' (in control of the data) as responsible for breach reporting even where the breach occurs at a third-party processor, rather than imposing joint/several notification duties on both parties.

Claims (1):

  • The OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.

Security MeasuresGreen

Principle 4.7 requires that personal information be protected by security safeguards appropriate to the sensitivity of the information.

Claims (1):

  • Principle 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.

Breach NotificationAmber

Organizations must report to the OPC and notify affected individuals of breaches posing a 'real risk of significant harm'; the timeline standard is criticized as vague and the Commissioner has recommended a fixed 7-day reporting requirement.

Claims (3):

  • Organizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.
  • Significant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.
  • PIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.

Retention And DisposalAmber

Breach records must be retained for two years and produced to the OPC upon request; no general retention-limit statute for all personal information was located.

Claims (1):

  • PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.
Category narrative90 words

Accountability is a foundational PIPEDA principle: organizations remain responsible for personal information transferred to third-party processors and must ensure comparable protection contractually. Statutory DPIA and DPO-appointment thresholds (GDPR Art.35/37 analogues) are absent from PIPEDA; the Commissioner has recommended a PIA requirement for high-risk processing as part of stalled reform. Breach notification is mandatory where a 'real risk of significant harm' exists, but the timeline standard ('as soon as feasible') is criticized as vague, and the OPC lacks direct fining power for breach-reporting failures (referral to the Attorney General is required).

Sources and claims (8)
  1. ConfirmedOPC — PIPEDA's accountability principle provides that an organization remains responsible for the personal information it has transferred to a third party for processing.observed
  2. ProbableIAPP — The Commissioner recommended that the proposed Consumer Privacy Protection Act include a privacy impact assessment requirement for high-risk activities, particularly for technologies such as AI, to help identify and mitigate privacy risks.observed
  3. ConfirmedIAPP — PIPEDA requires organizations to keep records of all breaches of security safeguards regardless of whether there is a real risk of significant harm, and these records must be retained for two years and provided to the OPC if requested.observed
  4. ConfirmedOPC — The OPC has found it reasonable to interpret the principal organization as having control of personal information and therefore responsibility for breach reporting in respect of a breach occurring at a third-party processor, rather than requiring both parties to report.observed
  5. ConfirmedOPC — Principle 4.7 of PIPEDA Schedule 1 stipulates that personal information shall be protected by security safeguards appropriate to the sensitivity of the information.observed
  6. ConfirmedOPC — Organizations subject to PIPEDA are required to report to the Privacy Commissioner of Canada breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals and to notify affected individuals about those breaches.observed
  7. ConfirmedOPC — Significant harm under subsection 10.1(7) of PIPEDA includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.observed
  8. ProbableOPC — PIPEDA's breach-reporting timeline is vague ('as soon as feasible'), and the Commissioner has recommended organizations be required to report a privacy breach to the OPC within 7 days of detection.observed

#

Adequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.

Primary frameworkPIPEDA (no dedicated transfer chapter) + EU Commission Decision 2002/2/EC as reviewed 2024
Traffic-light rationale — AmberAdequacy status is currently confirmed and stable, but is explicitly conditioned by the European Commission on further legislative modernization of PIPEDA that has stalled since the death of Bill C-27 in 2025.

Sub-modules (6)

Transfer MechanismsAmber

PIPEDA does not contain separate and explicit rules governing trans-border data flows; instead it requires transparency about foreign processing and requires organizations to ensure a comparable level of protection via contractual or other means for third-party processing.

Claims (2):

  • PIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.
  • PIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.

Adequacy ReceivedGreen

Not applicable in the outbound sense for CA-ON as a receiving jurisdiction from the EU; see adequacy_granted for Canada's inbound adequacy from the EU.

Adequacy GrantedGreen

The European Commission concluded in January 2024 that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA, as part of an 11-jurisdiction periodic adequacy review; the UK separately maintains its own adequacy regulations covering PIPEDA-subject recipients.

Claims (3):

  • On January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.
  • Canada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.
  • Canada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.

Sccs And BcrsAmber

PIPEDA has no dedicated SCC/BCR statutory mechanism; where adequacy does not apply (e.g., non-federally-regulated employee data or intra-provincial data outside PIPEDA's ambit), practitioners rely on contractual safeguards akin to SCCs, and the OPC is exploring the Global CBPR Forum as a further certification-based mechanism.

Claims (2):

  • The Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.
  • The Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.

Transfer Impact AssessmentAmber

No statutory TIA requirement equivalent to Schrems II practice was identified as a formal PIPEDA obligation; risk-assessment practice is industry-guidance-driven rather than legislated.

Absence provenance: unavailable. Searched: PIPEDA transfer impact assessment requirement, OPC TIA guidance PIPEDA.

Data LocalisationGreen

No general data-localisation mandate was identified under PIPEDA or Ontario's sectoral statutes.

Absence provenance: unavailable. Searched: PIPEDA data localisation requirement, Ontario PHIPA data residency requirement.

Category narrative87 words

PIPEDA contains no separate explicit trans-border data flow rules; instead it relies on transparency and accountability obligations requiring comparable protection when data is transferred abroad for processing. Canada (for PIPEDA-covered commercial operators) holds a long-standing EU adequacy decision, most recently reconfirmed in the Commission's January 2024 periodic review, with the next review expected around 2028; the UK separately recognizes PIPEDA-covered transfers via its own adequacy regulations. Adequacy is partial: it excludes the substantially-similar provincial regimes of Alberta, British Columbia and Quebec, and generally excludes non-federally-regulated employee data.

Sources and claims (7)
  1. ConfirmedOPC — PIPEDA does not contain separate and explicit rules governing trans-border data flows; it requires organizations to be transparent about their data practices, including when personal information is transferred to a foreign jurisdiction.observed
  2. ConfirmedOPC — PIPEDA clarifies that organizations remain responsible for personal information transferred to a third party for processing and must ensure, through contractual or other means, a comparable level of protection.observed
  3. ConfirmedEUR-Lex — On January 15, 2024, the European Commission concluded a review of 11 adequacy decisions, including Canada's, and concluded that Canada continues to provide an adequate level of protection for personal data transferred from the EU to recipients subject to PIPEDA.observed
  4. ProbableOPC — Canada's adequacy decisions are reviewed every four years, so the OPC expects the next EU adequacy review around 2028.observed
  5. ConfirmedIAPP — Canada's partial adequacy designation for EU-to-Canada transfers applies only to Canadian organizations subject to PIPEDA in respect of the transferred data, not to provinces with substantially-similar laws (Alberta, British Columbia, Quebec) or to most non-federally-regulated employee data.observed
  6. ProbableOPC — The Commissioner supports exploration of alternative data transfer mechanisms such as Global Cross-Border Privacy Rules (CBPR) Forum certifications to provide businesses with regulatory certainty for transfers.observed
  7. ProbableOPC — The Commissioner has recommended that PIPEDA be amended to specifically address trans-border data flows to ensure personal information is appropriately protected prior to leaving Canada.observed

#

Health sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.

Primary frameworkPHIPA (health) + CASL (telecoms/e-marketing) + PIPEDA (federally-regulated employment)
Traffic-light rationale — AmberHealth sector overlay is robust and actively enforced (first PHIPA AMPs issued 2025); employment-data overlay is a documented, commissioner-flagged legislative gap; credit-scoring/insurance sectoral rules could not be confirmed in this pass.

Sub-modules (7)

Financial Sector OverlayAmber

Federally-regulated banks are directly subject to PIPEDA as federal works, undertakings or businesses (FWUBs); no distinct Ontario provincial financial-sector privacy overlay was identified.

Claims (1):

  • Federally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.

Health Sector OverlayGreen

PHIPA governs personal health information handled by Ontario health information custodians, administered by the IPC, and has been declared substantially similar to PIPEDA for health information purposes; the IPC has now issued its first monetary penalties under PHIPA.

Claims (2):

  • The Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.
  • The IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.

Telecoms And EprivacyGreen

CASL, the federal anti-spam law, is jointly enforced by the CRTC, OPC and Competition Bureau and separately amended PIPEDA regarding electronic address harvesting.

Claims (1):

  • At the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.

Employment DataRed

There is currently no privacy legislation applicable to non-federally-regulated Ontario employees; PIPEDA only covers employees/applicants of federally-regulated employers (FWUBs), a gap FPT Commissioners have formally flagged.

Claims (2):

  • There is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.
  • Canada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.

Credit And ScoringRed

No distinct Ontario or federal credit-scoring-specific data protection statute was located in this research pass.

Absence provenance: unavailable. Searched: Ontario credit scoring privacy law, PIPEDA credit reporting data rules.

EducationAmber

Ontario schools/universities are generally covered by provincial (FIPPA/MFIPPA) rather than PIPEDA rules, and Canadian privacy regulators have jointly resolved to strengthen children's privacy protections in EdTech.

Claims (2):

  • Municipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.
  • Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

InsuranceRed

No distinct Ontario or federal insurance-sector data protection overlay was located in this research pass; general PIPEDA/PHIPA rules would apply by default.

Absence provenance: unavailable. Searched: Ontario insurance sector privacy law, PIPEDA insurance data rules.

Category narrative81 words

Ontario's sectoral overlays are concentrated in health (PHIPA, with a mature IPC administrative-monetary-penalty regime now in active use) and public-sector/child-welfare (FIPPA, CYFSA), while general private-sector employment privacy remains a documented statutory gap outside AB/BC/QC — non-federally-regulated Ontario employees have no dedicated statutory privacy protection distinct from PIPEDA, which itself only covers federally-regulated employers' employees/applicants. Telecoms/e-marketing is separately regulated federally via CASL (CRTC/OPC/Competition Bureau shared enforcement). No distinct Ontario/federal statutory regime for credit-scoring or insurance-sector data was located in this research pass.

Sources and claims (8)
  1. ConfirmedOPC — Federally regulated employers such as banks are subject directly to PIPEDA in respect of the personal information of their employees and applicants for employment.observed
  2. ConfirmedOneTrust DataGuidance — The Information and Privacy Commissioner of Ontario is the regulator responsible for ensuring compliance with the Personal Health Information Protection Act, 2004, which has been found to be substantially similar to PIPEDA for personal health information.observed
  3. ConfirmedOneTrust DataGuidance — The IPC's enforcement powers under PHIPA allow administrative monetary penalties up to CAD 50,000 for individuals and CAD 500,000 for organizations, and the IPC has now issued its first PHIPA monetary penalties, including against a doctor and clinic for unauthorized use of health data.observed
  4. ConfirmedOPC — At the federal level, spam and other electronic threats are regulated by Canada's anti-spam legislation (CASL) and related provisions in PIPEDA, with the OPC sharing enforcement responsibility with the CRTC and the Competition Bureau.observed
  5. ConfirmedOPC — There is currently no privacy legislation applicable to non-federally-regulated employees in provinces across Canada, with the exception of Alberta, British Columbia and Quebec which have their own provincial privacy laws.observed
  6. ConfirmedOPC — Canada's Federal, Provincial and Territorial Privacy Commissioners have called on governments to acknowledge legislative gaps in employee privacy protection and take action to close those gaps, particularly given increased electronic monitoring.observed
  7. ConfirmedOPC — Municipalities, universities, schools, and hospitals are generally covered by provincial laws rather than PIPEDA.observed
  8. ProbableOneTrust DataGuidance — Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.observed

#

Direct marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.

Primary frameworkCASL + PIPEDA (address harvesting provisions)
Traffic-light rationale — AmberDirect marketing and address-harvesting rules are mature and actively enforced via CASL/CRTC precedent, but adtech-specific concepts (opt-out signals, clean rooms, cross-context advertising) have no dedicated CA-ON statutory analogue.

Sub-modules (6)

Cookies And TrackersAmber

No CA-ON-specific cookie-consent statute (ePrivacy-style) was located; general PIPEDA consent principles apply to tracking technologies by default.

Absence provenance: unavailable. Searched: Ontario cookie consent law, PIPEDA cookie tracking rules.

Dark PatternsAmber

The OPC provides guidance on deceptive design patterns that may influence individuals into giving away more personal information online, though this is guidance rather than a standalone dark-patterns statute.

Claims (1):

  • The OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.

Opt Out SignalsRed

No statutory recognition of browser-based opt-out signals (e.g., Global Privacy Control) was located under PIPEDA or Ontario statutes.

Absence provenance: unavailable. Searched: PIPEDA Global Privacy Control recognition, Ontario opt-out signal law.

Clean Rooms And DcrRed

No Canadian federal or Ontario-specific clean-room/data-collaboration-room regulatory framework was located.

Absence provenance: unavailable. Searched: Canada data clean room regulation, PIPEDA data collaboration room rules.

Cross Context AdvertisingAmber

PIPEDA has no CPRA-style 'sale'/'share' distinction for cross-context advertising; consent-based rules apply generally to disclosure for advertising purposes.

Absence provenance: unavailable. Searched: PIPEDA cross-context advertising rules, Canada sale of personal information advertising rules.

Direct MarketingGreen

CASL requires express or implied consent, sender identification and unsubscribe mechanisms for commercial electronic messages; implied consent based on an existing business relationship expires after two years; PIPEDA separately prohibits address harvesting with very limited exceptions.

Claims (3):

  • CASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.
  • Implied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.
  • With very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.
Category narrative84 words

Direct marketing/commercial electronic messaging is governed federally by CASL (jointly enforced by CRTC, OPC and Competition Bureau) requiring express or implied consent, sender identification and functioning unsubscribe mechanisms; implied consent from an 'existing business relationship' expires after two years. PIPEDA separately prohibits address harvesting. CRTC enforcement precedent (CompuFinder, $1.1M AMP) demonstrates meaningful sectoral penalty capacity despite PIPEDA itself lacking fining power. No dedicated statutory framework for opt-out signals (e.g., Global Privacy Control), clean rooms/data-collaboration rooms, or cross-context-advertising 'sale/share' concepts (CPRA-style) was located for CA-ON.

Sources and claims (4)
  1. ConfirmedOPC — The OPC provides consumer guidance on deceptive design patterns that may influence individuals into giving away more of their personal information online.observed
  2. ConfirmedIAPP — CASL expressly prohibits sending a new commercial electronic message unless the recipient has consented to receiving it (express or implied), and the message must identify the sender, contain contact information, and include an unsubscribe mechanism.observed
  3. ConfirmedIAPP — Implied consent under CASL based on an existing business relationship carries a two-year time limit from the date of implied consent.observed
  4. ConfirmedOPC — With very limited exceptions, PIPEDA prohibits address harvesting (automated compilation of electronic addresses), and engaging in or using harvested lists risks contravening the meaningful-consent obligation under PIPEDA.observed

#

No comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.

Primary frameworkNone in force (AIDA/CPPA died with Bill C-27, 2025) — governed ad hoc via PIPEDA general principles and IPC/OPC guidance
Traffic-light rationale — RedNo comprehensive AI statute is in force federally following AIDA's death; ADM transparency rights remain proposal-stage only, while active regulator guidance (OPC biometrics, IPC-OHRC AI principles) partially fills the gap without statutory force.

Sub-modules (6)

Profiling RestrictionsRed

No statutory Art.22-style profiling restriction is in force in Canada; the stalled CPPA would have introduced algorithmic transparency provisions.

Claims (1):

  • The CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.

Automated Decision Making TransparencyRed

The proposed (now-stalled) CPPA would have provided algorithmic transparency and a right of individuals to obtain an explanation of automated decisions; this is not currently in force.

Claims (1):

  • PIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.

Ai Risk AssessmentsRed

AIDA, Canada's first attempt at cross-sector AI risk-assessment legislation for high-impact systems, died with Bill C-27's failure to pass before Parliament's January 2025 prorogation and has not been reintroduced.

Claims (2):

  • The prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.
  • As of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.

Biometric RegimeAmber

The OPC is finalizing guidance on biometrics for public and private sector organizations following a fall 2023/winter 2024 public consultation; no standalone biometric statute exists.

Claims (1):

  • The OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.

Genetic DataAmber

No standalone genetic-data statute was located; the IPC has published 12 guardrails specifically for police use of investigative genetic genealogy, addressing privacy and human-rights concerns.

Claims (1):

  • Ontario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.

State Surveillance CarveoutsAmber

Detailed evidence on national-security carve-outs specific to CA-ON was not located in this research pass; general federal Privacy Act national-security exemptions are understood to exist but require further primary-source verification.

Absence provenance: unavailable. Searched: Canada national security privacy exemption Ontario, PIPEDA law enforcement disclosure exemption scope.

Category narrative104 words

Canada currently has no comprehensive federal AI statute in force: the Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died when Parliament was prorogued on January 6, 2025, and has not been reintroduced as of this research pass. Algorithmic-transparency/ADM-explanation rights were only proposed (via the stalled CPPA) and are not currently in force. The OPC is finalizing biometrics guidance following a 2023-2024 consultation, and Ontario's IPC has been highly active on AI/biometric governance specifically — co-issuing AI-use principles with the Ontario Human Rights Commission, publishing 12 guardrails for police use of investigative genetic genealogy, and joining a multi-provincial investigation into OpenAI's ChatGPT.

Sources and claims (6)
  1. ProbableIAPP — The CPPA, part of the now-dead Bill C-27, would have provided algorithmic transparency and a right of individuals to require an explanation of how automated decisions about them were made — this reform has stalled.observed
  2. ProbableIAPP — PIPEDA was ill-suited to address automated or algorithmic decision-making, and the proposed CPPA provided for algorithmic transparency and the right of individuals to require an explanation of automated decisions about them, but this bill was never enacted.observed
  3. ConfirmedOneTrust DataGuidance — The prorogation of Canada's Parliament on January 6, 2025, following the resignation of Prime Minister Justin Trudeau, ended debate on Bill C-27, which included the Artificial Intelligence and Data Act.observed
  4. ProbableIAPP — As of the 45th Parliament (beginning May 26), there is not yet an indication if Bill C-27 or its AIDA component will be reintroduced or replaced by a different legislative vehicle for AI regulation.observed
  5. ProbableOPC — The OPC is finalizing guidance on biometrics for public and private sector organizations following a public consultation conducted in fall 2023 and winter 2024.observed
  6. ProbableOneTrust DataGuidance — Ontario's IPC published guidelines for police use of investigative genetic genealogy, addressing privacy and human rights concerns with 12 guardrails.observed

#

A concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.

Primary frameworkCYFSA Part X (children in care) + PIPEDA general consent principles
Traffic-light rationale — AmberA concrete statutory protection exists for children in provincial care (CYFSA Part X) and regulator attention to children's/EdTech privacy is active, but general age-verification, parental-consent, and dependent-adult regimes were not confirmed in this pass.

Sub-modules (5)

Age VerificationRed

No statutory age-verification threshold was located for CA-ON; PIPEDA applies contextual consent standards rather than a fixed age threshold.

Absence provenance: unavailable. Searched: PIPEDA age of consent minors, Ontario age verification statute.

Minor Profiling BansRed

No statutory minor-specific profiling ban was located; the stalled CPPA reform was criticized by commentators for not going far enough on protecting children's/youth privacy.

Claims (1):

  • Commentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.

Education SettingsAmber

Canadian federal/provincial/territorial privacy commissioners issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

Claims (1):

  • Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.

Dependent AdultsRed

No dependent-adult-specific privacy protection regime was located for CA-ON in this research pass.

Absence provenance: unavailable. Searched: Ontario dependent adult privacy protection law, PIPEDA elderly incapacity data protection.

Category narrative77 words

Ontario's most direct statutory protection for a vulnerable group is Part X of the CYFSA, which gives children in the child-welfare system a right to reasonable privacy and possession of personal property. Federal/provincial commissioners have jointly targeted children's privacy in EdTech and flagged that stalled federal reform (CPPA) did not go far enough on children's/youth privacy. No age-verification or COPPA/GDPR-Art.8-style parental-consent threshold statute was located for CA-ON in this research pass; dependent-adult-specific protections were similarly not identified.

Sources and claims (2)
  1. ProbableIAPP — Commentators noted that children's/youth privacy has received much more domestic and international attention, and that the now-dead CPPA did not go as far as it could or should have in protecting children and youth.observed
  2. ProbableOneTrust DataGuidance — Canadian privacy authorities issued a joint resolution to protect children's privacy in EdTech, emphasizing shared responsibility and proactive privacy measures.observed

#

Ontario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.

Primary frameworkPIPEDA enforcement provisions (ss.11-17, s.28) + PHIPA s.61.1 AMP regime
Traffic-light rationale — AmberOntario's IPC now has and is actively using real monetary-penalty power (PHIPA), but the federal OPC — the primary regulator for most Ontario private-sector data — still lacks direct fining authority, and PIPEDA modernization (to add order-making/AMP powers via the stalled CPPA) remains unresolved.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The OPC cannot prosecute PIPEDA offences or issue fines directly, but can refer possible offences to the Attorney General for prosecution by the Director of Public Prosecutions; the IPC, by contrast, has direct AMP power under PHIPA up to CAD 500,000 for organizations.

Claims (3):

  • The OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.
  • The time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.
  • Following amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.

Enforcement Activity IndexAmber

The OPC closed 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26 amid a significant rise in complaint volumes; the IPC issued its first-ever PHIPA monetary penalties in the same period.

Claims (2):

  • The OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.
  • The OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.

Regulator Funding And CapacityAmber

The Commissioner has stressed the need for stable, permanent OPC funding to keep pace with growing complexity of privacy issues, having previously operated on temporary funding.

Claims (1):

  • The Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.

Collective Redress And Class ActionsAmber

No dedicated statutory class-action mechanism specific to PIPEDA/PHIPA was independently confirmed in this pass; case law (e.g., Hopkins v. Kay) has permitted individual civil suits for PHIPA breaches, suggesting a common-law avenue exists alongside statutory complaint processes.

Claims (1):

  • In Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.

Private Right Of ActionAmber

CASL originally contemplated a private right of action for contraventions, planned to come into force in a later implementation phase; current operative status requires primary-source confirmation.

Absence provenance: unavailable. Searched: CASL private right of action current status 2026.

Claims (1):

  • CASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).

Recent Developments 180DGreen

Within the last ~180 days: Commissioner Dufresne testified on Bill C-15's PIPEDA data-mobility amendments before House INDU (Jan 2026) and Senate committees; the OPC/Quebec/BC/Alberta joint OpenAI ChatGPT investigation concluded (May 2026); Dufresne was elected Chair of the Global Privacy Assembly; and the OPC-IPC MOU continues to enable cross-statute joint investigations.

Claims (3):

  • In January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.
  • The Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.
  • Commissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.
Category narrative122 words

Enforcement is bifurcated: the federal OPC operates largely as an ombudsman under PIPEDA with no direct order-making or fining power — it can investigate, issue findings, refer offences to the Attorney General for prosecution, or seek a Federal Court order (application window extended from 45 days to one year) — while Ontario's IPC has direct administrative-monetary-penalty power under PHIPA (up to CAD 500,000 for organizations) and has now used it for the first time. The OPC saw a significant rise in complaint volumes in FY2025-26. Recent developments (within ~180 days) include Bill C-15's proposed PIPEDA data-mobility amendments (Commissioner testimony January-February 2026), the concluded joint OPC/Quebec/BC/Alberta investigation into OpenAI's ChatGPT (May 2026), and the Commissioner's election as Chair of the Global Privacy Assembly.

Sources and claims (11)
  1. ConfirmedOPC — The OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to the possible commission of an offence to the Attorney General of Canada, which could lead to prosecution by the Director of Public Prosecutions.observed
  2. ConfirmedOPC — The time limit for court applications under PIPEDA was changed from 45 days to one year (or a longer period the Court may allow) by the 2015 Digital Privacy Act amendments.observed
  3. ConfirmedOneTrust DataGuidance — Following amendments to Section 61.1 of PHIPA and Regulation O.Reg. 329/04, the IPC's enforcement powers were widened to increase administrative monetary penalties to a maximum of CAD 50,000 for individuals and CAD 500,000 for organizations.observed
  4. ConfirmedOPC — The OPC closed a total of 975 Privacy Act complaints and 302 PIPEDA complaints through early resolution in FY2025-26.observed
  5. ConfirmedOPC — The OPC experienced a significant increase in the number of complaints received under both the Privacy Act and PIPEDA during FY2025-26.observed
  6. ProbableIAPP — The Commissioner stressed the need for stable, permanent OPC funding to keep up with the growing complexity of privacy issues, noting the Office had been operating on temporary funding.observed
  7. ProbableOneTrust DataGuidance — In Hopkins v. Kay, the Ontario Court of Appeal held that PHIPA was not a complete code, giving individuals the ability to sue for breaches involving unauthorized use and disclosure of personal health information.observed
  8. UncertainIAPP — CASL's implementation schedule contemplated a private right of action provision reaching force following an earlier implementation phase (targeted for July 1, 2017 at the time regulations were finalized).observed
  9. ConfirmedOPC — In January 2026, Commissioner Dufresne appeared before the House of Commons Standing Committee on Industry and Technology regarding proposed PIPEDA amendments (data mobility) introduced in Bill C-15, and later appeared before Senate committees in February 2026.observed
  10. ConfirmedOPC — The Commissioner concluded a joint investigation with Quebec, British Columbia and Alberta privacy regulators into OpenAI's ChatGPT in May 2026, finding the complaint well-founded and conditionally resolved.observed
  11. ConfirmedOPC — Commissioner Dufresne concluded a one-year term as Chair of the Canadian Digital Regulators Forum in May 2025 and was elected Chair of the Global Privacy Assembly, and the OPC updated its information-sharing MOU with the IPC Ontario in 2025.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 3 failing check(s).

schema_validpass
min_architecture_patterns0
min_red_flags0
min_controls0
worked_examples_count0
decision_tree_nodes0
counterparty_diligence_questions0
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
board_briefing_presentFAIL
every_practical_object_has_source_idFAIL
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ontario, Canada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 60 claim(s) (61 category placement(s)), 28 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (33 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy received
Art. 49Cross-Border & Adequacysccs and bcrs
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redresscollective redress and class actions
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (priv.gc.ca, EUR-Lex Commission decisions, DataGuidance-sourced primary statute citations) and T3 (IAPP/DataGuidance secondary analysis) sourcing. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, sectoral_watch (health), adtech_and_commercial_privacy (direct marketing), enforcement_and_redress, and recent_developments_180d modules rest on strong T1 primary-source grounding (OPC/IPC official pages, EU Commission adequacy review). algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups modules rest more heavily on T3 secondary reporting (IAPP) given the absence of any current in-force federal AI or children's-privacy statute post-AIDA's death; several sub-modules (credit_and_scoring, insurance, opt_out_signals, clean_rooms_and_dcr, age_verification, parental_consent, dependent_adults, state_surveillance_carveouts) carry explicit absent_field_provenance because no CA-ON-specific statutory source was located despite targeted searches.

Unresolved questions (5):

  • Current in-force/suspended status of CASL's private right of action provision as of 2026 requires primary-source (Industry Canada / ISED) confirmation.
  • Whether Bill C-15's data-mobility provisions have progressed beyond committee testimony toward Royal Assent since February 2026.
  • Whether a successor bill to the dead AIDA/CPPA has been formally tabled in the current (45th) Parliament.
  • Precise scope of national-security/law-enforcement carve-outs under PIPEDA s.7(3) as applied in Ontario was not independently verified against primary statutory text in this pass.
  • Whether Ontario has any credit-scoring or insurance-sector-specific privacy overlay not surfaced by this research pass.

Escalate to primary-source review: yes