PIPEDA is Canada's federal private-sector privacy law, governing how organizations collect, use, and disclose personal information in the course of commercial activity. It is the privacy backdrop against which Canada's Consumer-Driven Banking framework is being built — the existing consent-and-data-handling regime that any Canadian financial-data sharing has to work within until, and after, open banking goes live.
PIPEDA
PIPEDA — the Personal Information Protection and Electronic Documents Act — is Canada’s federal private-sector privacy law, governing how businesses handle personal information in commercial activity, on a consent-and-reasonable-purposes model.
- Consent-based handling - Organizations must obtain meaningful consent to collect, use, or disclose personal information, and limit it to reasonable purposes.
- The pre-open-banking regime - Like the US GLBA, PIPEDA governed financial data long before Canada legislated consumer-driven banking; the new framework sits on top of it.
- Under reform - PIPEDA has been the subject of modernization efforts, which matter for how a future open-banking regime handles data.
PIPEDA is part of why Canada’s open-banking story is one of absence: the privacy law existed, the banks handled data under it, but nothing required them to let a consumer port that data through an API. Canada did not lack privacy regulation; it lacked an access mandate — and the consumer-driven banking framework is the attempt to add one on top of PIPEDA.
Referenced in API Evangelist papers
This regulation shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this regulation in the context of a real sector.
The State of Canadian Banking APIs
The existing privacy regime Canada's not-yet-live consumer-driven banking framework is layered on.