
Operating Across Provinces: Reconciling Canada's Privacy Regimes
Four or five overlapping privacy laws, one organisation. How to build a single programme that satisfies the strictest of them without running four in parallel.
GuardsArm Team
Security Experts

A company headquartered in Calgary, with staff in Vancouver, customers in Toronto and a data centre in Montreal, is subject to PIPEDA, Alberta PIPA, BC PIPA and Quebec Law 25 simultaneously. Running four privacy programmes is neither affordable nor coherent.
The workable approach is one programme built to the strictest requirement on each individual obligation — which is not the same as building everything to Quebec's standard.
Which regime is strictest, obligation by obligation
Reading across that picture:
| Obligation | Build to |
|---|---|
| Governance and privacy officer | Quebec — named and published |
| Assessments before new systems | Quebec and Alberta HIA — a gate, not a formality |
| Transfers outside the province | Quebec — assessment required, including elsewhere in Canada |
| Breach reporting | The federal register plus the fastest applicable clock |
| Employee information | BC and Alberta — notify purposes in advance |
| Individual rights | Quebec — portability and automated decision explanation |
| Consent for sensitive information | Quebec — express and separated |
Notice that BC and Alberta are strictest on employee information, not Quebec. A programme built solely to Law 25 leaves an employee-notification gap in two provinces.
The single-programme design
One policy set, with provincial annexes. A core privacy policy carrying the strictest common position, plus short annexes for the genuinely local rules — the Alberta HIA Minister notification, the BC employee notice, the Quebec transfer assessment.
One register, one assessment method. A single incident register satisfies the federal requirement and feeds every provincial report. A single harm assessment method, applied to the strictest threshold in scope, avoids relitigating the question per jurisdiction.
One privacy officer, with named provincial contacts where a local presence is expected.
One inventory, tagged by jurisdiction. This is the part organisations skip and the part everything else depends on. You cannot apply Quebec's transfer rules without knowing which data relates to Quebec residents and where it physically goes.
The traps
- Assuming a substantially similar province displaces PIPEDA entirely. It does not, for cross-border flows or federally regulated businesses. See PIPEDA compliance.
- Reading "outside Quebec" as meaning outside Canada. Ontario counts.
- Forgetting employee data because the customer-facing programme was the one with a budget.
- Health information hiding inside an ordinary business. Benefits administration, occupational health and employee assistance programmes can pull a general employer toward health privacy obligations.
- Treating the inventory as a one-off. It ages the moment a new SaaS tool is signed.
Consent is where the regimes diverge most
The obligations converge more than people expect, except on consent, where the provinces genuinely differ in ways a single policy has to accommodate.
| Regime | Consent posture |
|---|---|
| PIPEDA | Consent-based, meaningful consent, form scaled to sensitivity |
| Alberta PIPA | Consent with defined exceptions; opt-out available in circumstances |
| BC PIPA | Similar to Alberta; deemed consent in defined cases |
| Quebec Law 25 | Strictest — express and separate consent for sensitive information, granular purposes |
Build to Quebec's standard for sensitive information and you satisfy the others. Build to PIPEDA's and you will be offside in Quebec on exactly the data where a complaint is most likely.
A realistic sequence
Organisations that succeed at this do it in a fixed order, because each step depends on the last:
- Inventory, tagged by jurisdiction and physical location
- Gap assessment against the strictest applicable standard per obligation
- Core policy plus provincial annexes
- One register and one harm assessment method
- Gate new systems with an assessment step in project intake
- Review annually, and whenever you enter a new province
Skipping to step three is the common mistake. A policy written before the inventory describes an organisation you might have rather than the one you do.
Where to start
Build the jurisdiction-tagged inventory. Which systems hold personal information, whose residents it relates to, where it physically sits, and who it is shared with. Every downstream decision — transfer assessments, notification routing, retention — depends on it, and no amount of policy work substitutes for having it.
GuardsArm builds unified privacy programmes for organisations operating across Canadian jurisdictions. See multi-province compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


