Rules
Provincial privacy rules for campaign data: PIPEDA vs Quebec Law 25 vs Alberta PIPA
Provincial privacy rules for campaign data differ across PIPEDA, Quebec Law 25 and Alberta PIPA, covering consent, breach notice and cross-border flows.
What to take away
- Provincial privacy rules for campaign data in Canada are not one law: PIPEDA covers federally regulated businesses and provinces without their own private-sector statute, while Quebec Law 25 and Alberta PIPA set stricter local terms.
- Consent models differ by province: Quebec and Alberta generally require opt-in for marketing, PIPEDA allows implied consent in defined circumstances, and Quebec's regime carries the sharpest penalties.
- Breach notification duties run on separate clocks and thresholds, so one incident can trigger two or three reports.
- Cross-provincial data flow rule: the law of the province where the individual resides usually follows the subscriber, not the sender's address.
- A data map plus vendor contract terms are the cheapest way to satisfy all three regimes at once.
Three regimes, one campaign list: PIPEDA, Quebec Law 25 and Alberta PIPA
A single subscriber list can sit under three statutes at the same time. That is the starting fact for any Canadian campaign team.
The federal Personal Information Protection and Electronic Documents Act applies to private-sector organizations in provinces that have no substantially similar private-sector law of their own. It also covers federally regulated sectors everywhere, including banks, telecoms and airlines.
The Office of the Privacy Commissioner of Canada publishes the privacy laws in Canada overview that sets out how PIPEDA and the provincial regimes fit together.
Quebec's Law 25 modernized its private-sector statute and added teeth: higher administrative penalties, a duty to report certain breaches, and privacy-by-default settings. It applies to enterprises carrying on business in Quebec, which captures most national retailers and SaaS vendors with Quebec customers.
Alberta's Personal Information Protection Act governs provincially regulated private-sector organizations in Alberta. It is built on an opt-in consent model, with limited exceptions, and it has its own breach reporting duty to the Office of the Information and Privacy Commissioner of Alberta.
British Columbia has its own private-sector law, and it is also deemed substantially similar to PIPEDA. Ontario, the Prairies, Atlantic Canada and the territories rely on PIPEDA for most private-sector activity, with health-specific statutes in several provinces.
That patchwork matters for list management. A Halifax retailer emailing subscribers in Montreal, Calgary and Vancouver is running three consent tests, not one. The same is true for a Toronto agency managing lists on behalf of clients in each province.
One practical shortcut: build the list to the strictest standard you face, then document why. Teams that default to Quebec's opt-in rule rarely fail an Alberta or PIPEDA review. Teams that default to implied consent often do.
Keep the federal statutes themselves close. The Consolidated Acts P section holds PIPEDA and the Privacy Act, and the Consolidated Acts index is the fastest route to locating provincial privacy legislation by name.
Consent models compared: opt-in, opt-out and implied consent windows
Consent model differences are where campaigns break. The three regimes do not define valid consent the same way.
PIPEDA uses a knowledge-and-consent standard. Consent can be express or implied, depending on the sensitivity of the information and the reasonable expectations of the individual. For marketing email, the Office of the Privacy Commissioner expects meaningful consent: plain language, a clear purpose, and an easy way out.
The privacy for businesses guidance walks through those consent and list management duties.
Quebec Law 25 is stricter. Consent must be clear, free and informed, and it must be requested separately from other terms when the purpose is marketing. Bundled consent buried in a general terms-of-service clause is a weak position. Law 25 also expects privacy settings to be at the most protective level by default.
Alberta PIPA consent is opt-in as a rule. An organization needs express consent for the collection, use or disclosure of personal information unless an exception applies. Alberta recognizes implied consent in narrow cases, such as when a person volunteers information for an obvious purpose, but marketing to a purchased list is not one of them.
CASL sits on top of all three. Canada's anti-spam law requires consent for commercial electronic messages, and it is enforced by the CRTC. A campaign that passes PIPEDA can still fail CASL. Start from a CASL-compliant email template for any Canadian send, because the consent record and unsubscribe mechanics overlap with every privacy review.
Implied consent windows are mostly a CASL concept, not a privacy one. Where a business relationship exists, CASL allows a period of implied consent for messages, and the privacy statutes still apply to the personal information itself. Treat the two as separate tests that both need to pass.
For list hygiene, that means three fields on every record: the basis of consent, the date it was given, and the source. If a regulator asks, the record is the answer.
What each regime requires in a privacy policy and a list record
A privacy policy is not a legal ornament. Under all three regimes it is the document that tells people what you do with their data, and it must match practice.
PIPEDA expects a policy that is readily available, written in understandable language, and specific about purposes, retention and complaint routes. The policy must name a privacy officer or contact point.
Quebec Law 25 goes further. It requires the policy to be clear and to state the purposes and categories of information, and it adds a duty to inform before using technology that identifies or profiles a person. Quebec also requires a person in charge of the protection of personal information, with the title published.
Alberta PIPA requires a privacy policy that is available on request and that explains purposes and how to contact the privacy officer. Alberta also requires notification of the individual when personal information is collected, directly or through an agent.
On the list record itself, the practical requirements converge:
- Consent basis recorded as express, implied or exempt, with the statutory ground named
- Date and time consent was captured
- Source of the record: form, event, purchase, partner or list rental
- The exact wording the subscriber agreed to, versioned
- Unsubscribe and withdrawal dates, with the action taken
- Purpose of use, including any secondary marketing or analytics use
- Retention period and the scheduled deletion date
That record set satisfies the substance of all three regimes. Quebec and Alberta will want the purpose and contact details visible to the individual; PIPEDA will want the consent to be meaningful and the policy to be honest.
Retention is the quiet failure point. PIPEDA says keep personal information only as long as needed for the purpose. Quebec Law 25 requires a retention schedule and its publication in some cases. Alberta expects destruction or anonymization once the purpose ends. If your list has records from 2016 with no activity, that is a finding waiting to happen.
Access requests are the other test. Individuals can ask what you hold and ask for correction. Quebec and Alberta set their own response timelines and processes, and PIPEDA requires a response within a set period, with limited extensions. A campaign team that cannot pull one subscriber's full record on request is not compliant, regardless of the policy text.
Breach notification duties and the timelines that apply
Breach notification Canada rules are layered. One incident can trigger federal and provincial duties at once.
Under PIPEDA, an organization must report a breach of security safeguards to the Office of the Privacy Commissioner if it creates a real risk of significant harm. It must also notify affected individuals in that case, and keep records of every breach, reportable or not, for a set period. The threshold is risk of significant harm, not any incident.
Quebec Law 25 requires notification to the Commission d'acces a l'information and to affected individuals when a breach presents a risk of serious injury. Quebec also requires an incident register and, in some cases, notification to other organizations that may be able to reduce the risk.
Alberta PIPA requires an organization to report a breach to the Commissioner without unreasonable delay when there is a real risk of significant harm, and to notify individuals when there is a real risk of significant harm to them. Alberta also requires the organization to keep records of the breach.
Three practical consequences for campaign teams:
- Write an incident response plan that names the decision-maker for the risk assessment and the regulator contact for each province.
- Keep a breach register from day one, even for near misses, because all three regimes expect records.
- Test the plan with a tabletop exercise on a realistic scenario, such as a compromised email platform holding subscriber records.
Timelines are where teams slip. Federal and Alberta reporting is expected promptly, and Quebec expects notification with diligence. Do not wait for a full forensic report before calling the regulator. Report what you know and supplement later.
Marketing platforms are a common breach source because they hold consent records, opens, clicks and sometimes purchase history. If your email service provider is breached, you may be the organization that must notify, not the vendor. The contract should say who calls whom and within what window.
Cross-provincial data flows and which law follows the subscriber
The cross-provincial data flow rule is simpler than most teams assume: the law that protects the individual generally follows the individual's province of residence, not the sender's province of operation.
A Vancouver company emailing a Montreal subscriber should expect Quebec Law 25 to apply to that subscriber's personal information. A Calgary company emailing an Ontario subscriber is generally in PIPEDA territory for that record. A Montreal company emailing an Alberta subscriber should meet Alberta PIPA terms for that record.
Where a province has its own substantially similar law, that law governs provincially regulated organizations operating in the province. PIPEDA still applies in federally regulated sectors and in provinces without their own private-sector statute.
Transfers across borders add another layer. Quebec Law 25 requires a privacy impact assessment before transferring personal information outside Quebec in some circumstances, and it expects comparable protection. PIPEDA expects organizations to be accountable for personal information transferred to a third party, including a processor, and to protect it with contractual or other means.
For campaign data, that produces a rule of thumb: map the subscriber's province, apply the strictest applicable consent standard to that record, and keep the transfer terms in writing. A single national list can be run this way, but only with province-level tags on every record.
Technology choices interact with this. Profiling, automated decision-making and AI-driven segmentation now attract explicit attention from regulators, and the Office of the Privacy Commissioner's AI and technology privacy guidance is the reference point for how campaign data governance should treat those tools.
If a model scores subscribers or predicts churn, that use needs a stated purpose and, in Quebec, a clear notice.
Building a campaign data map that satisfies all three regimes
A data map is the artefact that turns three statutes into one operating procedure. Build it once, keep it current, and most audits become a lookup exercise.
Start with the subscriber lifecycle, not the database schema. Where does a record enter, who touches it, where does it rest, and when is it destroyed?
- List every collection point: signup forms, checkout, event badges, webinars, partner lists, purchased lists and offline sign-ups.
- For each point, record the consent basis, the exact wording shown, and the province of the individual.
- Trace the record through every system: CRM, email platform, analytics, ad audiences, call centre and any AI scoring tool.
- Name the legal basis for each use, including secondary uses such as lookalike audiences.
- Set a retention period per record type and automate deletion.
- Assign an owner for each system and a contact for access requests.
- Review the map quarterly and after any platform change.
A worked example makes the stakes concrete. Suppose a Toronto retailer runs a contest that collects email addresses in Ontario, Quebec and Alberta. The Ontario records can rely on the contest terms if consent is meaningful.
The Quebec records need clear, separate consent and a published privacy contact. The Alberta records need opt-in consent with notice of the purpose. One campaign, three consent treatments, one data map that shows all three.
A campaign brief template must contain a privacy section for exactly this reason. Consent basis, province coverage and retention should be briefed before creative, not after legal review.
If your team works from a standard email marketing template, check that the footer carries the privacy policy link, the identification line and the unsubscribe path. Those three elements serve both CASL and the privacy regimes.
Run the map against an a/b testing plan template before each major send. It catches the record-keeping gaps that a policy review will not.
Vendor and processor contracts: what to ask before transferring data
Most campaign data sits with vendors: email platforms, CRMs, analytics tools and agencies. The contract is where accountability is either preserved or lost.
All three regimes keep the originating organization accountable for personal information transferred to a processor. That means the contract must do real work.
Ask these questions before any transfer:
- Does the vendor act only on your instructions, and is that stated in writing?
- Where is the data stored and processed, including backups and support access?
- Does the vendor use your data for its own purposes, including model training?
- What are the breach notification duties and the window for telling you?
- How does the vendor handle access and correction requests from individuals?
- What happens to the data at termination: deletion, return, or both, and on what schedule?
- Will the vendor sign the Quebec-required terms if you have Quebec subscribers?
Quebec Law 25 expects a written mandate before transferring personal information to a service provider, and it expects the transfer to be limited to the stated purpose. Alberta PIPA expects reasonable security arrangements and notification duties to flow through. PIPEDA expects comparable protection by contractual means.
Sub-processors are the usual gap. If your email platform uses a third-party delivery network in another country, that is a transfer you should know about and disclose. Ask for the current sub-processor list and the notice period for changes.
Agencies sit in the middle. If an agency manages a list on your behalf, the agency is a processor and you remain accountable. The contract should say who owns the list, who can export it, and what happens when the engagement ends.
A canadian marketing budget template review is a useful way to see how other teams structured those terms.
Finally, keep the vendor inventory next to the data map. A vendor with no contract clause on breach notice is a reporting risk you are carrying.
A comparison table for consent, retention and individual access requests
The table below summarizes the operating differences. It is a planning aid, not legal advice, and the statutes and regulator guidance remain the authority.
| Item | PIPEDA | Quebec Law 25 | Alberta PIPA |
|---|---|---|---|
| Consent default for marketing | Express or implied, based on sensitivity and expectations | Clear, free, informed, separate for marketing purposes | Express consent as the rule, narrow implied exceptions |
| Privacy policy duty | Available, understandable, names a contact | Clear policy, published privacy officer title, notice for profiling | Available on request, explains purposes and contact |
| Breach reporting | Report to OPC if real risk of significant harm | Report to the Quebec commission and individuals if risk of serious injury | Report to Alberta commissioner without unreasonable delay, notify individuals |
| Breach records | Required for all breaches | Required register | Required records |
| Access and correction | Response within a set period, limited extensions | Own process and timelines | Own process and timelines |
| Retention | Only as long as needed for the purpose | Retention schedule required | Destroy or anonymize when purpose ends |
| Transfers outside the province | Accountable, protect by contract | Written mandate, privacy impact assessment in some cases | Reasonable security, notification duties flow through |
| Regulator | Office of the Privacy Commissioner of Canada | Commission d'acces a l'information du Quebec | Office of the Information and Privacy Commissioner of Alberta |
Read the table by column when you onboard a new data source, and by row when you review an incident. The two directions catch different failures.
Two habits keep the table useful. First, tag every subscriber record with a province so the applicable column is known. Second, review the table when a platform changes its data practices, because a new sub-processor or a new AI feature can move a row.
Common questions
Does PIPEDA apply if my business is in Ontario? Yes, for most private-sector organizations in Ontario, because Ontario has no general private-sector privacy statute and PIPEDA fills the gap. Federally regulated businesses in Ontario are covered by PIPEDA in any case.
Can I rely on implied consent for an email list under Alberta PIPA? Generally no for marketing. Alberta PIPA treats express consent as the rule, with narrow implied exceptions that do not cover purchased or rented lists. Build the record on express consent.
Do I need separate consent for Quebec subscribers if I already have CASL consent? Yes, the tests are separate. CASL consent satisfies the anti-spam requirement, while Quebec Law 25 sets its own standard for the personal information, including separate consent for marketing purposes.
Who do I notify if a breach affects subscribers in three provinces? Notify each regulator whose threshold is met and the affected individuals where required. That can mean the federal commissioner, the Quebec commission and the Alberta commissioner from a single incident.
How long can I keep inactive subscriber records? Only as long as needed for the stated purpose. Set a retention period per record type, automate deletion, and document the schedule, because all three regimes expect retention to be justified.
Which law governs a subscriber who moves provinces? Apply the law of the province where the individual resides at the time of the collection and use. Keep the province tag current, and re-check consent terms when a subscriber's province changes.
