Personal Information in the Private Sector

AuthorBarbara Von Tigerstrom
Legislation governing personal information in the private sector com-
mercial and other private organizations is a relatively recent addition
to the Canadian legal landscape, as compared to public sector infor-
mation and privacy legislation. A unique combination of federal and
provincial legislation now covers this field across Canada. The federal
statute, the Personal Information Protection and Electronic Docume nts Act,
was enacted in 2000 and came into effect in stages beginning in 2001.1
Part 1 and Schedule 1 of this Act deal with personal information, while
the remaining parts deal with electronic documents. It was predated by
the Quebec Act respecting the protection of personal information in the pri-
vate sector (Quebec Private Sector Act, in force since 1994),2 and Alberta
and British Columbia passed private sector statutes, both titled the Pe r-
sonal Information Protection Act (PIPA ), a few years later (both enacted in
2003 and in force 1 January 2004).3 This chapter will focus prim arily on
the federal legislation, but include some discussion of important differ-
ences and useful examples from the provincial legislation.
The enactment of PIPEDA was part of the federal government’s strat-
egy to promote electronic commerce,4 but its immediate impetus was the
adoption of the European Union (EU) Data Protection Directive.5 This
Directive, which took effect in 1998, established data protection prin-
ciples to be implemented in EU member states and, most significantly
for non-members like Canada, required them to prevent transfers of
personal data to countr ies that did not provide adequate protection. In
the absence of any comprehensive Canadian laws governing personal
information in the private sector out side of Quebec this would
have meant significant impediments for cross-border transfers of infor-
mation and thus for Canadian organizations engaging in international
business. In 2001, following the enactment of PIPEDA, the European
Commission adopted a decision stating that “Canada is considered as
providing an adequate level of protection for personal data transferred
from the Community to recipients subject to [PIPEDA].”6 The adequacy
of PI PEDA and other Canadian legislation will need to be reassessed
under the new European General Data Protection Regulation (GDPR),
which took effect in 2018, and this will inf luence potential reforms
of the legislation.7 In the meantime, the adequacy decision relating to
PIPEDA remains in force until amended, replaced, or repealed.8
Personal Infor mation in the Private Sector
The federal private sector framework is rather complex and unusual
in several respect s, including its relationship with provincial legi slation.
In order to provide a harmonized environment for business in Canada
and to ensure an adequate level of protection for the purposes of the
EU Data Protection Directive, it was important to put in place uniform
protection for personal information across Canada. The enactment of
PIPEDA is generally understood to be an exercise of the federal govern-
ment’s trade and commerce power, but the governance of personal infor-
mation falls at least partly under provincial jurisdiction over property
and civil rights in the province and local and private matters.9 Particu-
larly given that Quebec had already adopted its own provincial pri-
vate sector legislation, any attempt by the federal government to assert
comprehensive and exclusive jurisdiction in this area would have been
controversial, to say the least. The resulting compromise is reflected in
PIPEDA’s scope of application and in provisions that allow it to be dis-
placed by “substantially similar” provincial legislation. As will be dis-
cussed below, PIPEDA applies to personal information th at is collected,
used, or disclosed in the course of commercial activities or in connec-
tion with the operation of a federal work, undertak ing, or business.10 By
order of the Governor in Council, however, an activity or organization
(or class of activities or organizations) can be exempted from the appli-
cation of Part 1 of PIPEDA in respect of collection, use, or disclosure
of personal information within a province where substantially similar
provincial legislat ion applies.11 Even with this explicit accommodation
of provincial governments’ role, questions about the constitutionality of
PIPEDA have been raised, although never conclusively decided.12
