Overview
Federal private-sector privacy legislation applies broadly across Canada, with some provinces having substantially similar laws. Quebec's Law 25 imposes additional obligations on transparency, transfers and automated decision-making.
For individuals, the practical rights are access, correction, withdrawal of consent in some circumstances, and complaint to a commissioner. For organizations, the obligations follow the data — meaning a Canadian business can simultaneously be subject to European and US state privacy law.
Common Legal Issues
- Data breaches exposing personal or financial information
- Refused or incomplete access-to-information requests
- Unauthorized collection, use or disclosure of personal data
- Excessive monitoring, tracking or workplace surveillance
- Cross-border transfers and vendor data handling
- Automated decision-making and AI processing of personal data
Your Rights
- To know what personal information an organization holds and why
- To access your personal information and request correction
- To be notified of breaches that create a real risk of significant harm
- To withdraw consent in defined circumstances
- To complain to a federal or provincial privacy commissioner
- In Quebec, additional rights under Law 25 including on transfers
Regulators & Escalation Routes
- Office of the Privacy Commissioner of Canada (OPC)
- Oversees federal private-sector and public-sector privacy law.
- Provincial privacy commissioners
- Oversee provincial regimes; Quebec's Commission d'accès à l'information administers Law 25.
Regulatory bodies and their processes change. Confirm the current route with the organization before relying on it.
How This Applies to You
Individuals & consumers
The practical tools are an access request to find out what is held about you, a correction request, and a commissioner complaint if an organization does not respond properly. All are free.
Business owners & corporate executives
Compliance starts with a data inventory, then accurate privacy notices, vendor processing agreements, documented transfer mechanisms and a written breach-response plan. Notification windows are short and start when you become aware.
Private investors, family offices & high-net-worth individuals
Confidentiality of financial and family information, data held by advisers and family offices, reputational exposure from a breach, and cross-border transfer obligations across multiple jurisdictions are the dominant concerns.
Frequently Asked Questions
- Can I find out what a company knows about me?
- Generally yes. You can make an access request, and organizations must respond within the timeframe set by the applicable law. If they refuse or do not respond, you can complain to a commissioner.
- What are my rights after a data breach?
- Organizations must notify affected individuals where a breach creates a real risk of significant harm, and report to the regulator. You may also have a civil claim depending on the harm and jurisdiction.
- What is Quebec's Law 25?
- Quebec's modernized privacy law, which adds requirements including transparency, transfer assessments, and rules around automated decision-making — in some respects stricter than the federal regime.
- Does the GDPR apply to Canadian businesses?
- It can, where you offer goods or services to people in the EU or monitor their behaviour. Location alone does not determine it.
Need Help With a Legal Matter?
Provide some information about your situation and we'll help connect you with the right lawyer based on your legal issue.
This page is general information, not legal advice. LegalCounselNearMe is not a law firm and does not provide legal advice. Laws and processes vary by province and by your specific circumstances.