PIPEDA Compliance Guide for Winnipeg & Manitoba Businesses

Canada's federal privacy law imposes real obligations on Manitoba businesses - including mandatory breach reporting, financial penalties, and notification requirements. This guide explains what PIPEDA requires, who it applies to, and how to build a compliance program that protects your customers and your organization.

What is PIPEDA?

The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law. Enacted in 2000 and significantly strengthened in 2018 with the addition of mandatory breach reporting rules, PIPEDA governs how organizations collect, use, and disclose personal information in the course of commercial activity.

Personal information under PIPEDA is broadly defined - it includes any information about an identifiable individual. This covers names, email addresses, financial data, health information, IP addresses, browsing behaviour, employee records, and much more. If your business handles data about identifiable people, PIPEDA almost certainly applies to you.

Note: Manitoba does not have its own substantially similar private-sector privacy legislation (unlike Alberta and British Columbia), which means PIPEDA is the primary applicable law for most Manitoba businesses in commercial activity. Healthcare organizations in Manitoba are also subject to provincial PHIA (Personal Health Information Act) requirements.

Who Does PIPEDA Apply to in Manitoba?

PIPEDA is built around 10 Fair Information Principles that define how organizations must handle personal information. Understanding these is the foundation of any compliance program.

There are limited exemptions - purely personal or domestic activities, certain non-commercial non-profit activities, and journalistic, artistic, or literary purposes. But for the vast majority of Manitoba businesses, if you collect personal data, PIPEDA applies.

The 10 Fair Information Principles

PIPEDA is built around 10 Fair Information Principles that define how organizations must handle personal information. Understanding these is the foundation of any compliance program.

1. Accountability

Designate an individual responsible for privacy compliance (a Privacy Officer or equivalent).

2. Identifying Purposes

Identify why personal information is being collected before or at the time of collection.

3. Consent

Obtain meaningful consent for the collection, use, and disclosure of personal information.

4. Limiting Collection

Collect only the information necessary for identified purposes (data minimization).

5. Limiting Use, Disclosure & Retention

Use information only for the purposes it was collected. Don't retain it longer than necessary.

6. Accuracy

Keep personal information accurate, complete, and up to date.

7. Safeguards

Protect information with security appropriate to its sensitivity.

8. Openness

Be transparent about your privacy policies and practices.

9. Individual Access

Allow individuals to access their personal information and challenge its accuracy.

10. Challenging Compliance

Have a process for individuals to challenge your compliance with these principles.

Mandatory Breach Reporting Requirements

The most consequential change to PIPEDA in recent years is mandatory breach reporting, which came into force in November 2018. If your organization experiences a breach of security safeguards involving personal information that creates a real risk of significant harm to individuals, you have two distinct obligations:

1. Report to the Office of the Privacy Commissioner (OPC)

You must report the breach to the OPC as soon as feasible after determining a reportable breach has occurred. The report must include: a description of the circumstances, the date or period the breach occurred, a description of the personal information involved, the number of affected individuals, steps taken to reduce risk, and contact information for follow-up.

2. Notify Affected Individuals

You must directly notify affected individuals as soon as feasible. Notifications must be direct (email, letter, in person) when feasible, and must include enough information for individuals to understand the significance of the breach and steps they can take to protect themselves.

What Is "Real Risk of Significant Harm"?

This is the threshold that determines whether reporting is required. Significant harm includes: bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property.

Breach Record-Keeping: Even if you determine a breach does NOT meet the reporting threshold, PIPEDA requires you to keep a record of every breach of security safeguards. These records must be retained for 24 months and provided to the OPC upon request.

Penalties for Non-Compliance

Failing to maintain breach records

PIPEDA's enforcement has teeth. Organizations that knowingly violate the following requirements can face fines of up to $100,000 per violation:

Beyond financial penalties, a public breach incident can cause significant reputational damage - particularly for professional services firms, healthcare providers, and businesses in regulated industries where client trust is foundational.

Practical PIPEDA Compliance Checklist for Manitoba Businesses

Appoint a Privacy Officer - Designate someone responsible for privacy compliance. Document this role.

Conduct a Data Inventory - Map what personal information you collect, where it's stored, how it's used, and who has access.

Review and Update Your Privacy Policy - Ensure it accurately describes your practices, is publicly available, and uses plain language.

Implement Consent Mechanisms - Ensure you have documented consent for all personal data collection, especially for marketing communications.

Assess Your Technical Safeguards - Review encryption, access controls, MFA, network security, and backup practices against the sensitivity of the data you hold.

Create a Breach Response Plan - Document how you'll detect, contain, assess, and report a breach. Define roles and timelines.

Establish a Breach Record Log - Even for non-reportable incidents, create and maintain a log of all breaches of security safeguards.

Train Staff - Ensure all employees who handle personal information understand PIPEDA basics, how to recognize a breach, and who to notify internally.

Review Vendor Agreements - If you share personal data with third-party vendors (cloud providers, payroll, CRMs), ensure your contracts require appropriate protection.

Conduct Annual Reviews - Privacy programs aren't set-and-forget. Review and update your policies, practices, and safeguards at least annually.

How Exchange Technology Services Supports PIPEDA Compliance

PIPEDA compliance is both a legal and technical challenge. The "safeguards" principle requires that technical security measures be appropriate to the sensitivity of the data - and demonstrating that your safeguards are adequate is increasingly difficult without documented security controls, monitoring, and incident response capabilities.

Exchange Technology Services helps Winnipeg and Manitoba businesses build and maintain the technical side of their PIPEDA compliance program, including security assessments, vulnerability management, access control reviews, staff security awareness training, breach detection through our SOC, and incident response support. We can also help you document your security controls for the purposes of regulatory reporting or OPC inquiries.

Talk to a Compliance & Security Expert

Not sure if your current security posture meets PIPEDA's safeguards requirement? We'll assess your environment and give you a clear picture - for free.

Book a Free Assessment