Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
PIPEDA Fines Are About to Match GDPR's ScaleLaws and Regulations
5 min readFor Privacy Officers

PIPEDA Fines Are About to Match GDPR's Scale

You've been tracking PIPEDA enforcement for years, and the pattern's been consistent: investigations, findings, commitments, maybe a Federal Court order. The Office of the Privacy Commissioner of Canada (OPC) can't fine you. The ceiling's CAD $100,000, and only a court can impose it for a narrow list of offenses that require proving you knowingly broke the rules.

That ceiling is about to crack. Bill C-36, introduced in June 2026 and now at second reading, would replace PIPEDA's enforcement model with penalties capped at the higher of $25 million or 5% of global revenue. That's higher than GDPR’s 4% ceiling, and it comes with a new regulator that can impose fines directly, without waiting for the Federal Court.

If you're still treating PIPEDA as the low-stakes cousin of GDPR, these myths will cost you.

Myth 1: The Privacy Commissioner Can't Fine You, So PIPEDA Has No Teeth

Reality: The OPC can't fine you today, but it can make your year miserable and your non-compliance public.

The Commissioner investigates, compels documents, enters premises, questions staff under oath, and publishes findings. In 2025-26 alone, the OPC received 3,044 PIPEDA complaints and 696 breach reports affecting over 20 million Canadians. An investigation is routine, not rare.

When the OPC finds a violation, it issues recommendations. Ignore them, and the complainant has one year to apply to the Federal Court for a hearing. The court can order you to fix your practices, publish the correction, and pay damages. The Commissioner can join that application.

Bill C-36 would hand enforcement to a new Digital Safety and Data Protection Commission of Canada with direct penalty authority. Administrative penalties would be capped per investigation at the higher of $10 million or 3% of global revenue. Court-imposed offense fines would reach the higher of $25 million or 5%. You won't need to ignore a recommendation to face a penalty anymore.

Myth 2: PIPEDA Fines Are Only for Serious Offenses

Reality: Today, yes. Under Bill C-36, any contravention of the Act could trigger an administrative penalty.

Right now, the $100,000 ceiling applies only to five section 28 offenses: knowingly destroying personal information someone requested, knowingly failing to report a qualifying breach, knowingly failing to notify affected people, knowingly failing to keep breach records, punishing a whistleblower, or obstructing the Commissioner. That knowingly threshold is why prosecutions are rare.

Bill C-36 narrows that clause and adds administrative penalties for general non-compliance. Collecting more data than required, keeping it past its purpose, refusing a valid access request, or mishandling consent would all qualify. The penalty would be determined per investigation, not per violation, so a systemic issue affecting multiple obligations could hit the full cap in a single proceeding.

Myth 3: PIPEDA Damages Are Too Small to Worry About

Reality: Damages have stayed modest because the Federal Court awards them case-by-case, but Bill C-36 would add a private right of action.

The largest PIPEDA damages award to date is $20,000 in Chitrakar v. Bell TV, where the court ordered $10,000 in damages and $10,000 in exemplary damages for a credit check run without consent. Nammo v. TransUnion awarded $5,000 for an inaccurate credit report. Those amounts reflect individual harm in discrete incidents.

Bill C-36 would let individuals sue for damages once a finding of contravention is final or a court has found one. That shifts the calculus. A systemic violation affecting thousands of people wouldn't be limited to the Commissioner's investigation and a single complainant's damages claim. Each affected person could pursue their own remedy, and class actions become viable.

Myth 4: You Only Need to Worry If Someone Complains

Reality: The Commissioner can open an investigation without a complaint, and recent findings prove it.

Section 11 of PIPEDA lets the Commissioner initiate a complaint directly. In June 2026, the OPC found complaints against X and xAI well-founded but not yet resolved, over consent for using Canadians' personal information to generate sexualized deepfakes. The Commissioner opened those complaints itself in January 2026.

The joint investigation into OpenAI in May 2026 began with complaints, but the OPC's involvement showed multi-jurisdictional coordination with provincial regulators. The finding was conditionally resolved after OpenAI committed to filtering personal information from training data, formal retention policies, and quarterly compliance reports.

You don't control the trigger. The Commissioner monitors breach reports, follows public incidents, and coordinates with other regulators. If your practices draw attention, an investigation can start whether or not someone files a formal complaint.

Myth 5: Bill C-36 Won't Pass, So You Can Wait

Reality: Bill C-36 is the third attempt at reform, and it's already at second reading. Treating it as speculative is a planning failure.

Bill C-11 was introduced in 2020. Bill C-27 and its Consumer Privacy Protection Act were introduced in 2022 and died when Parliament was prorogued in January 2025. Bill C-36 was introduced in June 2026 and is now before the House for second reading as of September 2026.

The direction is clear: higher penalties, direct regulatory authority, and alignment with GDPR-scale enforcement. Even if passage takes another year, the gap between current PIPEDA obligations and your actual compliance posture is the risk. If you're not meeting PIPEDA's requirements today, Bill C-36's penalties will apply retroactively to the practices you're running now.

What to Do Instead

Start with breach handling. Section 10.1 requires reporting qualifying breaches to the OPC and notifying affected people. Section 10.3 requires logging every breach, reportable or not, and keeping those records for 24 months. If you're not doing both, you're exposed to a section 28 offense under current law and an administrative penalty under Bill C-36.

Audit your consent practices. The joint OpenAI finding turned on consent for scraped data, accuracy, and retention. The X and xAI finding turned on consent for generating deepfakes. If you're relying on implied consent, broad purpose statements, or indefinite retention, document your legal basis now and prepare to tighten it.

Map your data flows to PIPEDA's fair information principles in Schedule 1. Bill C-36's administrative penalties would apply to any contravention of Division 1 or 1.1, or any failure to follow those principles. That includes accountability, identifying purposes, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance. If you can't demonstrate compliance with each principle for each processing activity, you're building liability.

Finally, budget for the new enforcement reality. Legal, technical, and operational changes take time and resources. Waiting until Bill C-36 passes means you'll be implementing fixes under the threat of a penalty investigation, not ahead of it.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like