One of the strictest anti-spam laws globally, requiring express or implied consent before sending commercial electronic messages, installing software, or altering transmission data. Penalties can reach $10 million per violation. Applies to any organization sending commercial electronic messages to or from Canada.
Personal Information Protection and Electronic Documents Act
PIPEDA — S.C. 2000, c. 5
Canada's federal private-sector privacy law, built on ten fair information principles. It requires meaningful consent for data collection, use, and disclosure, and gives individuals the right to access and challenge the accuracy of their personal data. Applies to private-sector organizations collecting personal information in the course of commercial activity across Canada.
Quebec Law 25 (Act to modernize legislative provisions as regards the protection of personal information)
Quebec Law 25 — S.Q. 2021, c. 25
Quebec's modernized privacy law introducing mandatory privacy impact assessments, breach notification, enhanced consent requirements, and the right to data portability. It is notably stricter than the federal PIPEDA. Applies to all private organizations collecting personal information in Quebec.