PIPEDA Privacy Requirements for Canadian Crypto Businesses: The 2026 Compliance Guide

PIPEDA Privacy Requirements for Canadian Crypto Businesses: The 2026 Compliance Guide
Table of contents
    • PIPEDA covers commercial activity anywhere in Canada, so a platform serving Canadians is caught whether or not it is based here, and Alberta, British Columbia and Quebec add their own statutes.
    • Anti-money-laundering rules force crypto firms to collect and keep data that privacy rules tell them to minimise, and reconciling the two is this sector’s central compliance problem.
    • Breaches creating a real risk of significant harm must be reported as soon as feasible, and every breach logged for 24 months.
    • Bill C-36 would replace PIPEDA’s rules with penalties reaching $10 million or 3 percent of global revenue.

    PIPEDA is Canada’s federal privacy law for private-sector businesses. It applies to any organisation that collects, uses or shares personal information during commercial activity in Canada, including crypto exchanges, brokers and wallet providers. It sets ten binding principles covering consent, collection limits, safeguards, retention and access rights.

    What Is PIPEDA?

    PIPEDA stands for the Personal Information Protection and Electronic Documents Act, the federal law that tells private businesses in Canada how they may handle information about people. It received royal assent on 13 April 2000 and was phased in until January 2004, when it reached all organisations engaged in commercial activity. The Office of the Privacy Commissioner of Canada, usually shortened to the OPC, enforces it.

    The law rests on a simple bargain. A business may collect information about a person only for purposes a reasonable person would consider appropriate, it must usually obtain consent first, it must protect what it holds, and it must let the person see it. Those duties are written into ten principles in a schedule attached to the Act, and every one is legally binding.

    The Act governs commercial activity specifically, meaning any transaction or conduct of a commercial character, and buying or selling crypto assets for customers is plainly commercial.

    Who Does PIPEDA Apply To?

    Because PIPEDA is federal legislation, the question of who it binds has both a geographic and a sectoral answer, and crypto businesses tend to be caught by both.

    Businesses That Are Covered

    PIPEDA applies to every private-sector organisation that collects, uses or discloses personal information in the course of commercial activity, which is the default across the country. It applies separately to federally regulated businesses and their employee records, a category covering banks, airlines, telecommunications firms and broadcasters, and it governs private business in Yukon, the Northwest Territories and Nunavut with no provincial substitute. Crypto trading platforms in Canada are not federally regulated in the banking sense, so they fall under the general commercial-activity rule, with an identical result.

    Foreign companies are caught as well, because PIPEDA reaches organisations outside Canada with a real and substantial connection to the country, meaning they market to Canadians, open their accounts and move their data. Offshore exchanges have sometimes assumed that incorporating in Seychelles or Malta puts them beyond Canadian reach. Enforcement history says otherwise. FINTRAC, the federal anti-money-laundering regulator, penalised Binance Holdings Limited $6,002,000 on 7 May 2024, and penalised Peken Global Limited, which operates as KuCoin, $19,552,000 on 28 July 2025. Both are foreign entities serving Canadian users.

    The Provincial Carve-Outs

    Three provinces have private-sector privacy laws the federal government has declared substantially similar to PIPEDA. Alberta and British Columbia each have a Personal Information Protection Act, written as PIPA, and Quebec has its Act respecting the protection of personal information in the private sector, amended by the package known as Law 25. Where one of those laws applies, it displaces PIPEDA for personal information collected, used and disclosed entirely inside that province, while PIPEDA still governs data once it crosses a provincial or national border. A platform with customers in Vancouver, Calgary, Montreal and Toronto is therefore operating under PIPEDA and three provincial statutes at once.

    Quebec’s regime is the strictest. Since September 2022 it has required organisations to report confidentiality incidents presenting a risk of serious injury to both the provincial regulator and affected individuals, to keep an incident register for five years, and to run privacy impact assessments before sending personal information outside the province. Its ceilings are the highest in Canada, reaching $10 million or 2 percent of worldwide turnover for administrative penalties and $25 million or 4 percent for penal offences. British Columbia sits at the other end, with no mandatory obligation to report breaches to its commissioner, and its 2026 reform bill leaves BC PIPA untouched.

    Exemptions That Rarely Help

    PIPEDA does contain exemptions, and knowing them saves time spent hoping one applies. The Act excludes federal government institutions, which answer to the Privacy Act instead, information collected for purely personal or domestic reasons, and collection for journalistic, artistic or literary purposes. Not-for-profits, charities and political parties generally sit outside it because they are not conducting commercial activity. None of those descriptions fits a crypto exchange, custodian, payment processor or public token issuer. A decentralised protocol with no corporate operator raises harder questions, but the moment a company runs a front end, holds customer funds or takes fees, PIPEDA applies.

    What Counts as Personal Information?

    Having established who the law binds, the next question is what it protects, and PIPEDA’s definition is deliberately wide.

    Personal information means information about an identifiable individual. It covers factual data such as a name, home address, date of birth, government identity number, IP address or account balance, and it covers subjective data, meaning opinions and assessments, which is why an internal note describing a customer as high risk is personal information about that customer. The test that matters is identifiability, and information is personal where there is a serious possibility an individual could be identified from it, alone or combined with other information reasonably available. That combination clause does a great deal of work in crypto.

    Wallet Addresses and Onchain Data

    A public wallet address looks like a random string, and firms sometimes argue it is anonymous. That argument is weak. Once an exchange links an address to a verified customer file, which every regulated platform does, the address becomes information about an identifiable individual in that company’s hands.

    The OPC has already shown how sceptical it is of weak de-identification. In PIPEDA Findings #2026-001 the Commissioner examined how Loblaw handled deleted PC Optimum loyalty accounts and found that stripping names and email addresses was insufficient, because retained records still held IP addresses and transaction histories that could be relinked to individuals. Histories tied to wallet clusters raise the same risk, so a crypto business treating pseudonymous records as outside the law is taking a position the regulator has already rejected.

    Two exclusions are worth remembering. Business contact information, meaning a person’s name, title and work contact details, sits outside PIPEDA when used solely to reach that person about their job. Truly anonymous data is outside the Act as well, though the bar is high enough to rule out simple masking, reversible tokenisation and most hashing.

    The 10 Fair Information Principles

    The ten principles in Schedule 1 are the operational core of the law, and each translates into a concrete task.

    # Principle What it requires What it looks like in crypto
    1 Accountability Name someone responsible, vendor data included A privacy officer and binding vendor contracts
    2 Identifying purposes Say why you collect, at or before collection Telling users at sign-up why ID is needed
    3 Consent Meaningful consent, express for sensitive data A consent step outside the terms of service
    4 Limiting collection Collect only what the purpose needs No credit history when four identity fields suffice
    5 Limiting use and retention Use data as stated, destroy it after Purging analytics while preserving AML records
    6 Accuracy Keep data correct enough for its purpose Letting customers fix a stale screening address
    7 Safeguards Protect data in proportion to sensitivity Encryption, key management, access controls
    8 Openness Make practices easy to find A plain-language policy naming data recipients
    9 Individual access Show people what you hold, fix errors Answering access requests within 30 days
    10 Challenging compliance Provide a complaints route, and use it A published channel with a named contact

    Three of those carry the most weight here. Consent comes first, because PIPEDA distinguishes express consent, where a person actively agrees, from implied consent inferred from circumstances, and sensitivity decides which is acceptable. The OPC treats financial and identity data as sensitive, so burying a clause in a forty-page terms document falls short of the requirement that consent be meaningful. Safeguards come second, because the Act demands security appropriate to sensitivity, and a platform holding passport scans, banking details and full transaction histories sits at the top of that scale.

    Individual Access Is Often Mishandled

    Individual access comes third, and it is the most often mishandled. An organisation has 30 calendar days to respond to an access request, with an extension of up to 30 further days available in narrow circumstances provided the customer is told inside the original window, and access should be free or at minimal cost. The OPC pursued this in PIPEDA Findings #2026-003, an investigation into Bell’s handling of an access request, confirming that slow responses are treated as substantive violations.

    Where FINTRAC Rules and PIPEDA Rules Collide

    Those ten principles become genuinely difficult once a second regulator issues instructions pointing the other way.

    Crypto businesses that exchange or transfer virtual currency for clients must register with FINTRAC as money services businesses under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and registration brings detailed data duties. Platforms must record client identity details, meaning name, address, date of birth and occupation, for virtual currency transfers and exchanges of $1,000 or more. They must create a large virtual currency transaction record whenever they receive $10,000 or more in one transaction, capturing the transaction hash, sending and receiving addresses, exchange rate and source, account details and the identity of everyone involved. The travel rule requires originator and beneficiary information to travel with outgoing transfers. Those records must be kept for at least five years.

    Collect Less Against Collect More

    The tension is easy to state, because PIPEDA’s fourth principle says collect only what your stated purpose needs while FINTRAC specifies a long list of details on a large share of your customers. The two coexist better than they first appear, since PIPEDA measures collection against a stated purpose and legal compliance is a legitimate purpose. Collecting occupation is proportionate when a federal regulation requires it. The problem lies in everything gathered beyond that list, because platforms routinely capture device fingerprints, geolocation, marketing attribution and behavioural analytics, none of which FINTRAC mandates. Each extra field needs its own justification, and possible future usefulness is not one.

    Five-Year Retention Against Limiting Retention

    The retention conflict is sharper, because FINTRAC requires five years while PIPEDA’s fifth principle requires destruction once the purpose is fulfilled. The resolution is to stop treating customer data as one undifferentiated pile. AML records carry a fixed legal retention period and must survive even when a customer closes their account and asks to be forgotten. Marketing profiles, support logs, session recordings and product analytics have no such protection, and keeping them indefinitely because deletion is inconvenient is exactly the failure identified in the Loblaw findings. A defensible schedule gives every category its own clock and its own legal basis, and it runs automatically rather than relying on someone remembering.

    One architectural habit keeps the regimes from pulling a programme apart. Separating regulated data from commercial data at the storage layer lets AML records sit in a controlled store with legal-hold protection while product data lives somewhere that can actually be purged.

    The Blockchain Problem: Data You Cannot Delete

    Retention schedules assume you control the database, and public blockchains break that assumption in a way privacy law has never fully resolved.

    A transaction written to a public chain is replicated across thousands of independent nodes, and no single operator can remove it. Where personal information reaches that chain, whether as an identifier in transaction metadata, a document hash or a token encoding something about its holder, the deletion right becomes impossible to honor normally. Canadian law has no provision addressing this, and the same problem has been argued under Europe’s GDPR for years.

    The workable approach keeps personal information offchain entirely, in conventional systems where it can be encrypted, controlled and deleted. Where a link is unavoidable, one accepted technique places only a cryptographic commitment onchain, so destroying the offchain record and its key leaves the onchain entry with nothing behind it. Product design determines whether this is possible, which is why privacy review belongs in the build process rather than the launch checklist.

    Biometric Identity Checks and the OPC’S Guidance

    Blockchain is one area where technology outruns the statute, and biometric onboarding is another, though here the regulator has spoken clearly.

    Selfie checks, liveness detection and face matching against an identity document are now standard in crypto onboarding. On 11 August 2025 the OPC published updated guidance on processing biometrics for businesses, and its position is firm. Biometric information is sensitive because it is permanently tied to a person’s body and can reveal further detail about health, race and gender characteristics. A password can be changed after a breach and a face cannot.

    The guidance asks businesses to establish an appropriate purpose before collecting biometrics at all, to obtain express consent, to test systems for accuracy and bias, to safeguard the data in line with its sensitivity and to be transparent throughout. Two questions follow for a crypto platform. Whether the template needs retaining once identity is confirmed is the first, and often it does not. Where the vendor performing the match stores its templates is the second, because accountability stays with you whoever runs the software. Quebec requires notification to its regulator before a biometric system enters service.

    Sending Customer Data Outside Canada

    Vendor arrangements raise the same accountability question at larger scale, because few Canadian crypto businesses keep all their data inside the country. Cloud hosting, blockchain analytics, sanctions screening and support tooling are often supplied from the United States or Europe, and PIPEDA permits this. The OPC’s long-standing position, reaffirmed in 2020 after a consultation that considered changing it, treats a transfer to a third party for processing as a use of the information rather than a disclosure, so fresh consent is not required.

    Two duties attach. The transferring organisation remains accountable and must use contractual or other means to ensure the processor provides comparable protection. It must also tell customers their information may be processed abroad and may therefore be reachable by that country’s courts and law enforcement. Quebec is stricter, requiring a privacy impact assessment before personal information leaves the province, and Bill C-36 would move the federal standard the same way.

    Breach Reporting: What to Do When Something Goes Wrong

    Cross-border processing widens the surface area for incidents, and Canada’s breach rules have been mandatory since 1 November 2018. Under PIPEDA an organisation must report a breach of security safeguards to the Privacy Commissioner as soon as feasible where it creates a real risk of significant harm, notify affected individuals just as promptly, and tell any other organisation able to reduce the harm. Significant harm is defined broadly, covering humiliation, reputational damage, loss of employment or business opportunity, financial loss, identity theft and credit record damage. Two factors decide whether the risk is real: how sensitive the information is, and how likely it is to be misused.

    The financial and identity data crypto platforms hold sits at the sensitive end of that scale, so most serious incidents at an exchange will cross the threshold, and the number of people affected does not enter the test. Separately, every breach must be recorded and the record kept for 24 months whether or not the threshold is met, and the Commissioner can ask to see that log at any time. Failing to report a reportable breach, or to keep these records, is an offence carrying a fine of up to $100,000.

    The Rules Change From Province to Province

    The rules change across provincial lines, which is why a national platform needs one playbook covering all of them.

    Jurisdiction Report to regulator Notify individuals Record keeping
    Federal (PIPEDA) Mandatory on real risk of significant harm, as soon as feasible Mandatory on the same test All breaches logged 24 months
    Alberta (PIPA) Mandatory where a real risk of significant harm exists Where the Commissioner directs, though most notify proactively Follow Commissioner guidance
    British Columbia (PIPA) Voluntary and encouraged Expected where risk of significant harm exists No fixed statutory period
    Quebec (Law 25) Mandatory and prompt for incidents risking serious injury Mandatory on the same test Incident register kept five years

    What Non-Compliance Costs Today

    Breach fines are only part of the exposure, and Canada’s federal enforcement picture is unusual by international standards. The Privacy Commissioner cannot issue fines for most PIPEDA violations, because the OPC investigates complaints, conducts audits and publishes findings with recommendations, none of which carry a direct financial penalty. Unresolved matters can go to the Federal Court, which can order changes to a company’s practices and award damages, including damages for humiliation. Statutory fines are confined to specific offences, chiefly obstructing an investigation, punishing a whistleblower and the breach failures described above, each capped at $100,000.

    The real cost usually sits elsewhere. A published OPC finding names the company and describes what it did wrong, and for a business whose product depends on customers trusting it with money and identity documents, that reputational damage outweighs the fine. Quebec’s Civil Code permits punitive damages independently of regulatory action, and securities regulators can attach conditions to a platform’s registration, with fewer than twenty platforms authorised to do business with Canadians on the Canadian Securities Administrators list dated 31 July 2026.

    Recent Updates and Future Outlook: Bill C-36

    The gap between PIPEDA’s modest penalties and the multi-million-dollar fines available in Europe and Quebec explains why Parliament keeps trying to rewrite the federal law. The previous attempt was Bill C-27, an omnibus package containing the Consumer Privacy Protection Act, a new data protection tribunal and the Artificial Intelligence and Data Act, and it died on 6 January 2025 when Parliament was prorogued during clause-by-clause committee review.

    Its successor arrived on 15 June 2026, when Bill C-36, the Protecting Privacy and Consumer Data Act, received first reading in the House of Commons and proposed to repeal Part 1 of PIPEDA. Parliament rose for the summer on 19 June 2026 and was scheduled to return on 21 September 2026, so the bill has not reached second reading and its final shape can still change.

    What the Bill Would Change

    Bill C-36 departs from its predecessor by dropping standalone AI legislation, routing appeals to the Federal Court instead of a specialised tribunal, and replacing Bill C-27’s strict anonymisation test with a risk-based standard asking whether there is a reasonably foreseeable risk of identification.

    Its substantive changes matter more. The definition of personal information would expand to include inferred data, reaching the risk scores and behavioural profiles platforms generate internally, and a new sensitive information category would attract heightened protection. Individuals would gain clearer rights to request deletion and to move data between providers. Organisations would face new transparency duties around automated decision-making such as account rejection and risk scoring, and privacy impact assessments would become mandatory before international transfers.

    Enforcement changes most of all. Private-sector oversight would move from the OPC to a new Digital Safety and Data Protection Commission of Canada, with the OPC keeping public-sector responsibility. That Commission could impose administrative penalties reaching $10 million or 3 percent of gross global revenue, whichever is greater, and serious offences prosecuted by indictment could reach $25 million or 5 percent. Individuals would gain a private right of action following a Commission finding.

    What to Do Before It Passes

    Preparation is straightforward, because the bill’s direction is already visible in Quebec’s law and the OPC’s recent guidance. An inventory of what personal data you hold, where it lives and why is useful under every version of the law. Retention schedules separating AML records from commercial data are useful now and mandatory later, and documenting how automated risk scoring reaches its decisions will be needed under the transparency provisions.

    A Practical PIPEDA Checklist

    Pulling those obligations together produces a short list a compliance team can work through.

    • Appoint a named privacy officer and publish their contact details.
    • Map every category of personal information you collect and record the legal basis for each field.
    • Rewrite the privacy policy in plain language, and separate the consent step for identity and financial data from the terms of service.
    • Build a retention schedule keeping AML records five years and deleting everything else on a documented clock, then test that the jobs run.
    • Put written data protection terms in every vendor contract, covering KYC, hosting, analytics and support.
    • Maintain a breach log for 24 months, answer access requests within 30 days, and run a privacy impact assessment before data leaves Canada or a biometric system goes live.

    Frequently Asked Questions (FAQ)

    Does PIPEDA apply to small businesses? +

    Yes. PIPEDA has no revenue threshold and no employee-count exemption, so a two-person crypto startup handling customer identity data carries the same core obligations as a national exchange. Size changes the scale of the programme rather than the duty itself, and Bill C-36 would formally allow proportionate requirements for smaller enterprises.

    Does PIPEDA apply to a crypto exchange based outside Canada? +

    Yes, where the exchange has a real and substantial connection to Canada, usually meaning it markets to Canadians and opens their accounts. Regulators have enforced against offshore operators, including the $19,552,000 FINTRAC penalty imposed on Peken Global Limited, trading as KuCoin, on 28 July 2025.

    Is a wallet address personal information under PIPEDA? +

    It is, once your business can link it to an identifiable person, which happens the moment a verified customer file is attached. A wallet address in isolation may identify nobody, but PIPEDA asks whether identification is seriously possible using other information reasonably available, and an exchange always holds that other information.

    Do I have to report every data breach to the Privacy Commissioner? +

    No. You must report a breach creating a real risk of significant harm, judged on the sensitivity of the information and the probability of misuse. You must keep a record of every breach of security safeguards for 24 months regardless of whether it met that threshold.

    What is the maximum fine under PIPEDA today? +

    The current maximum is $100,000 per offence, applying to a narrow set of failures: missing a reportable breach, keeping no breach records, obstructing an OPC investigation and retaliating against a whistleblower. Bill C-36 would raise the administrative ceiling to $10 million or 3 percent of gross global revenue.

    Can I delete customer data if FINTRAC requires me to keep it? +

    Not the records FINTRAC covers. Anti-money-laundering records must be kept at least five years, and a deletion request does not override that obligation. Data outside the regulated set, such as marketing profiles and analytics, should still be deleted once its purpose has been met.

    When will Bill C-36 become law? +

    No date is fixed. It received first reading on 15 June 2026 and had not reached second reading when Parliament rose on 19 June 2026, with sittings scheduled to resume on 21 September 2026. Committee study and amendments follow, and two previous federal privacy bills failed to complete that process.

    BitcoinCrypto ATMsRegulation
    Bitcoin ATM KYC Requirements in Canada
    Bitcoin ATM operations in Canada are strictly regulated under federal anti-money laundering laws, enforced by FINTRAC (Financial Transactions and Reports Analysis Centre of Canada). Every operator must formally register as a Money Services Business (MSB) before turning on a machine. Transactions below CAD $1,000 do not require identity verification, though operators are still required to […...
    7 hours ago
    Regulation
    When Does a Crypto Business Fall Under Canada’s RPAA?
    A crypto business falls under Canada’s Retail Payment Activities Act when it performs at least one of five defined payment functions, does so as a business activity rather than incidentally, ties that function to an electronic funds transfer made in Canadian or foreign currency, and falls inside the Act’s geographic scope without qualifying for an […]...
    23 hours ago
    Regulation
    Canada’s Crypto Travel Rule: Required Data and Transfer Decisions
    The required travel rule data for a virtual currency transfer is the name, address, and account number or other reference number (if any) of the person or entity who requested the transfer, plus the name, address, and account number or other reference number (if any) of the beneficiary. The commonly cited CAD 1,000 threshold appears […]...
    3 days ago