Quick answer:
PIPEDA is Canada's federal privacy law and it applies to essentially every Shopify store handling customer data for a commercial purpose. Quebec, Alberta, and British Columbia have their own substantially similar laws, and Quebec's Law 25 carries much larger penalties than PIPEDA does on its own. Failing to report a qualifying breach under PIPEDA can carry a fine up to 100,000 dollars, and a single complaint is enough for the Office of the Privacy Commissioner to open an investigation. AI agents that touch customer data, from a support chatbot to a HubSpot marketing agent, fall inside the same obligations as any other system processing personal information.
Most Canadian merchants treat privacy compliance as something that applies to banks and hospitals, not a Shopify store shipping out of Fredericton or Moncton. That assumption gets more expensive every year. PIPEDA has covered commercial activity across the country since 2004, cookie consent and data-mapping expectations have tightened since, and Quebec's Law 25 introduced enforcement with real financial teeth to a province that represents close to a fifth of the Canadian population.
What has changed more recently is the shape of the data itself. A store's customer data used to sit in Shopify, an email platform, and a CRM, all systems a privacy policy could describe in a few sentences. Now that same data also flows through AI agents answering support tickets, drafting marketing sequences, and handling B2B quote requests, and that flow needs to show up in the privacy program too. This guide covers what PIPEDA and the provincial laws actually require of an online store, what getting it wrong costs, and how to build compliance that holds up as the store keeps adding automation.
01. What PIPEDA Actually Requires From Your Online Store
The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies to any organization that collects, uses, or discloses personal information in the course of commercial activity, and a Shopify store selling goods for money is a commercial activity by definition. That coverage includes order data, account and login details, email and SMS marketing lists, payment and billing information, loyalty program activity, and the behavioural data your pixels and analytics tools collect on-site.
PIPEDA is built around ten fair information principles: accountability, identifying purposes for collection, meaningful consent, limiting what you collect, limiting how long you use, disclose, and retain it, keeping information accurate, safeguarding it appropriately, being open about your practices, giving individuals access to their own data, and providing a way to challenge your compliance. None of these are exotic requirements for a well-run store, but few merchants have ever written them down against their actual Shopify setup.
For a wholesale or B2B Shopify store, the same rules apply to the individual buyers at customer companies, not just consumer end customers. A purchasing manager's name, direct email, and order history are personal information under PIPEDA even though the transaction itself is business to business.
Why it matters: PIPEDA is not a niche regulation for large enterprises, it is the baseline legal framework for every piece of customer data your Shopify store already holds.
02. Federal Law vs Quebec, Alberta, and BC's Own Rules
Quebec, Alberta, and British Columbia each have their own private-sector privacy law that Ottawa has declared substantially similar to PIPEDA: Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, and Alberta and BC's respective Personal Information Protection Acts. When a provincial law is deemed substantially similar, it displaces PIPEDA for activity that stays inside that province, while PIPEDA continues to apply to interprovincial and international transfers of personal information regardless of where the business is based.
In practice, most Atlantic Canadian merchants shipping across the country and into the US are governed primarily by PIPEDA for their overall data handling. Quebec is the province that demands separate, deliberate attention: Law 25 layers on stricter consent and transparency rules and penalties an order of magnitude larger than PIPEDA's own, so a store with meaningful Quebec order volume needs a Law 25-specific review rather than assuming a PIPEDA-only policy already covers it.
This is the same pattern Quebec merchants are already used to from Bill 96's language requirements: the province sets a higher bar than the rest of the country, and treating Quebec customers as an afterthought creates compliance exposure that a general Canadian policy does not resolve.
Why it matters: a single generic privacy policy written for "Canada" usually understates what Quebec actually requires, and Quebec is the jurisdiction with the penalties large enough to notice.
03. What Non-Compliance Actually Costs
PIPEDA itself does not carry the large administrative penalties GDPR or Quebec's Law 25 do. Its sharpest financial teeth sit around breach handling: failing to report a breach that creates a real risk of significant harm, or failing to keep the breach records the law requires, is an offence carrying a fine of up to 100,000 dollars per violation. Quebec's Law 25 is a different scale entirely, with administrative penalties running up to 10 million dollars or 2 percent of worldwide turnover, and penal fines up to 25 million dollars or 4 percent of turnover for the most serious offences.
A federal replacement bill that would have brought PIPEDA's own penalties much closer to that scale, introducing percentage-of-revenue fines nationally, has been introduced and stalled more than once since 2022, most recently dying when Parliament prorogued in January 2025. Treat stronger federal penalties as coming, not as already in force, and build your program to the standard that will hold up either way.
The statutory fine is rarely the real cost. A mishandled breach or a public Office of the Privacy Commissioner finding becomes a reputational event with your customer base, and mishandled personal information is an increasingly common trigger for customer class actions in Canada. Enforcement does not require a government audit to find you: the OPC can open an investigation from a single complaint, filed by a customer, a competitor, or an advocacy group, the same pattern Quebec's OQLF uses for Bill 96.
the year PIPEDA's coverage extended to commercial activity across all of Canada
the maximum fine per offence for failing to report a qualifying breach or keep required records
is enough for the Privacy Commissioner to open an investigation into your store
Why it matters: the statutory fine is real, but the bigger risk is a public finding or a class action that a properly documented privacy program would have prevented.
04. Comparing Your Compliance Options
Most Shopify merchants land in one of four positions on privacy compliance. They are not equally defensible, and the gap between "we have a privacy policy" and "we have a privacy program" is exactly where most of the risk sits.
| Approach | Setup effort | Ongoing cost | Compliance standing |
|---|---|---|---|
| No privacy policy, default Shopify checkout only | None | $0 | Non-compliant |
| Generic template policy, no consent tracking | Low | Low | Risky, undocumented consent |
| Consent platform, reviewed policy, documented data map | Moderate | Moderate, app plus review time | Strong, recommended |
| Full program: privacy officer, vendor audits, breach plan | High | High, ongoing governance | Strong, right-sized for larger operations |
For most Canadian manufacturers, wholesalers, and DTC brands, the third row, a consent platform paired with a policy that reflects an actual data map, is the right target. A full governance program with a dedicated privacy officer is usually more structure than a mid-sized merchant needs, though it becomes appropriate once you are handling sensitive categories of data or operating at a scale where a breach would affect a large customer base.
Why it matters: a generic template policy feels like it checks the box, but it is the option most likely to fail a real review because it does not describe what your store actually does with data.
05. Building It Right: Consent, Minimization, and Your Privacy Policy
A compliant privacy program starts with an honest data map: what personal information your Shopify checkout collects, what your email and SMS platform holds, what your CRM stores, what any AI tools touch, and what every installed app can access. Most merchants are surprised by how many apps have standing access to customer data once they actually list them out, since each Shopify app installed over the years typically requested broad permissions at setup and rarely gets revisited.
Consent needs to match what you actually do with the data, not a boilerplate statement. This overlaps directly with what CASL already requires for email and SMS marketing consent, so the two compliance efforts should be built together rather than as separate projects: the same consent record that satisfies CASL for a marketing message should feed the same data map that satisfies PIPEDA's accountability principle.
Data minimization is the principle merchants skip most often. Every checkout field, every custom form, and every app asking for account access should have a stated purpose, and fields collected "in case we need it later" are exactly the kind of over-collection that turns a routine breach into a bigger one. A privacy policy that accurately reflects a minimized, mapped data flow is a policy that holds up under review, where a generic template copied from another store does not.
Why it matters: the privacy policy is the last step, not the first, and a policy built before the data map is complete is describing a store that does not actually exist.
06. Where AI Agents Change the Risk
AI agents do not create a separate privacy law, but they change what your existing PIPEDA obligations touch, and most merchants have not updated their data map to reflect it. A support agent reading order history to answer a ticket, a HubSpot Breeze agent drafting a marketing sequence from purchase behaviour, a prospecting agent working a lead list, or an AI receptionist taking a B2B phone order is all processing personal information the same way a human employee would, and it needs to appear in your privacy program the same way.
Three questions worth answering for every AI tool in your stack: where does the customer data go once the agent processes it, how long does the AI vendor retain it, and does your vendor agreement with that provider include appropriate data-handling and confidentiality terms. These are accountability and openness obligations PIPEDA already imposes, they simply now extend to a new category of vendor most merchants have not thought to ask these questions of.
This is not a reason to avoid AI automation, and the productivity case for tools like Shopify Sidekick, HubSpot Breeze agents, and custom procurement or accounts payable agents remains strong for Canadian manufacturers and wholesalers. It is a reason to document the data flow deliberately as you adopt each tool, the same way you would document a new payment processor or shipping integration, rather than treating an AI feature as invisible because it lives inside a platform you already trust.
A privacy policy that predates your AI tools is out of date.
If your store added a customer-facing chatbot, an AI marketing agent, or an automated quote system after your privacy policy was last written, the policy almost certainly does not describe what that tool does with customer data. Update it when you add the tool, not on the next annual review.
Why it matters: an AI agent that touches customer data is a new node in your data map whether or not anyone treated the rollout as a privacy decision at the time.
07. Breach Notification: What You Are Required to Do
PIPEDA's mandatory breach reporting duty applies when a breach of security safeguards creates a real risk of significant harm to an individual, a threshold commonly shortened to RROSH. Significant harm includes financial loss, identity theft, damage to reputation or business relationships, loss of employment or a business opportunity, and other serious impacts. When that threshold is met, you are required to report the breach to the Office of the Privacy Commissioner of Canada and notify the affected individuals, along with any other organization that could help reduce the resulting risk.
Below the RROSH threshold, reporting is not mandatory, but the record-keeping duty is not optional: every breach of security safeguards, reportable or not, must be documented and kept on file for at least 24 months, ready to produce if the OPC ever asks. A leaked customer list that turns out not to meet RROSH still needs a written record of what happened, what data was involved, and why it did not require notification.
A basic incident response plan for a Shopify store should cover who gets notified internally the moment a breach is suspected, how quickly the RROSH assessment gets made, a template for the individual notification if required, and who owns filing the OPC report. Building this before an incident, rather than improvising it during one, is the difference between a contained event and a compounding one.
Why it matters: the record-keeping duty applies to every breach regardless of severity, so a store with no incident log is already out of compliance even if nothing reportable has happened yet.
A note on scope: this guide is general information about PIPEDA and provincial privacy law as they apply to e-commerce, not legal advice. Obligations vary with your province, your data practices, and pending amendments. For decisions with legal consequences, such as breach notification, consult a privacy lawyer.
08. A Practical Rollout Plan
Treat PIPEDA compliance as a short, sequenced project rather than a single policy update.
Map every place customer data lives.
List Shopify checkout fields, your email and SMS platform, your CRM, every installed app, and any AI tools, along with what each one collects and why.
Cut what you do not need.
For every checkout field or app permission without a clear purpose, remove it or document why it stays. Data you never collected cannot leak.
Write a privacy policy that matches the map.
Replace a generic template with a policy that describes your actual data flows, including AI tools and third-party vendors, then have it reviewed against CASL consent requirements at the same time.
Add a Quebec-specific review if it applies.
If Quebec is a meaningful share of your customer base, confirm your consent language and transparency notices meet Law 25's stricter standard, not just PIPEDA's baseline.
Build the breach response plan before you need it.
Document who assesses RROSH, who files the OPC report, and who owns the 24-month incident log, so a real breach is a procedure, not an improvisation.
This work pairs naturally with the compliance projects most Canadian merchants are already running. If email and SMS consent has not been audited recently, the CASL compliance guide covers the marketing-specific half of consent that a PIPEDA data map should incorporate. And if Quebec is a meaningful market, the Bill 96 French-language guide covers the other major Quebec-specific obligation running in parallel with Law 25.
Why it matters: sequencing the work, map first, minimize second, document third, is what turns privacy compliance into a defensible program instead of a policy page nobody has re-read since it was published.
09. Frequently Asked Questions
What is PIPEDA and does it apply to my Shopify store?
PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada's federal private-sector privacy law. It applies to any organization that collects, uses, or discloses personal information in the course of commercial activity, which covers essentially every Shopify store selling to Canadian customers: order data, account details, email and SMS marketing lists, and analytics data all count. PIPEDA has applied to commercial activity across Canada since 2004, and it remains the operative federal law today, though a replacement bill with much larger penalties has stalled more than once since 2022 and should be treated as coming, not as current law.
Do I need a separate privacy approach for Quebec, Alberta, or BC customers?
Quebec, Alberta, and British Columbia each have their own private-sector privacy law declared substantially similar to PIPEDA, so their provincial law applies instead of PIPEDA for activity that stays inside that province. In practice, most Shopify merchants shipping across Canada and internationally are governed primarily by PIPEDA for their overall data handling, with Quebec's Law 25 the one that demands real extra attention: it carries far larger penalties and stricter consent and transparency rules than PIPEDA does on its own, so a store with meaningful Quebec order volume needs a Law 25-specific review, not just a PIPEDA-only policy.
What counts as personal information under PIPEDA for an ecommerce store?
Personal information is any data that can identify an individual, directly or in combination with other data: name, email, phone number, shipping and billing address, IP address, order history, payment details, loyalty program activity, and behavioural data collected through pixels, cookies, or on-site tracking. For a wholesale or B2B Shopify store, it also includes the names and contact details of individual buyers at customer companies, not just consumer end customers, since PIPEDA protects individuals regardless of whether the transaction itself is B2B.
What are the actual penalties for PIPEDA non-compliance?
PIPEDA itself does not carry the large administrative penalties GDPR or Quebec's Law 25 do. Its sharpest teeth are around breach handling: failing to report a breach that poses a real risk of significant harm, or failing to keep the required breach records, is an offence punishable by a fine of up to 100,000 dollars per violation. The bigger practical risk for most merchants is reputational and legal exposure beyond the statutory fine: a mishandled breach or an OPC finding of non-compliance becomes public, and it is increasingly a trigger for customer class actions in Canada.
Do I need to report every data breach to the Privacy Commissioner?
No. PIPEDA's mandatory reporting duty applies when a breach of security safeguards creates a real risk of significant harm to an individual, a standard commonly shortened to RROSH. Significant harm includes things like financial loss, identity theft, damage to reputation, or loss of employment or business opportunities. Below that threshold, reporting to the Office of the Privacy Commissioner is not required, but you are still legally required to keep a record of every breach, reportable or not, for at least 24 months, and to be able to produce that record on request.
Does using AI tools like HubSpot Breeze or Shopify Sidekick create new privacy obligations?
It does not create a separate law, but it changes what your existing PIPEDA obligations touch. An AI agent that reads order history to answer a support ticket, drafts a marketing email from customer purchase data, or handles a quote request is processing personal information the same as a human employee would, and your accountability and openness obligations extend to it: your privacy policy needs to reflect that AI tools process customer data, your vendor agreements with the AI provider need appropriate data-handling terms, and your data map needs to include where that data goes and how long the AI vendor retains it. This is a growing area of OPC guidance, and it is worth documenting deliberately rather than treating AI features as invisible to your privacy program.
How do I get started making my Shopify store PIPEDA compliant?
Start by mapping what personal information you actually collect and where it flows: Shopify checkout, your email and SMS platform, your CRM, any AI tools, and any third-party apps installed on your store. From there, write or update a privacy policy that accurately describes that map rather than a generic template, add a consent mechanism for cookies and marketing that matches what CASL already requires you to do for email and SMS, document your data retention and breach response process, and review Quebec-specific obligations separately if Quebec is a meaningful part of your customer base. Treat it as an ongoing program tied to your app and vendor changes, not a one-time policy update.
Key Takeaways
- PIPEDA applies to essentially every Shopify store handling Canadian customer data, and it has covered commercial activity nationally since 2004.
- Quebec, Alberta, and BC have their own substantially similar privacy laws, and Quebec's Law 25 carries penalties far larger than PIPEDA's own.
- Failing to report a qualifying breach or keep required records can carry a fine up to 100,000 dollars per violation, and a single complaint can trigger an OPC investigation.
- AI agents that touch customer data, from support chatbots to marketing agents, fall inside the same PIPEDA obligations as any other system processing personal information.
- A privacy policy is the last step, not the first: it needs to describe an actual, minimized data map, not a generic template.
Related Resources
The consent rules that overlap directly with your PIPEDA data map
The other major Quebec-specific obligation running alongside Law 25
The accessibility side of Canadian ecommerce compliance
How unifying customer data changes what your privacy map needs to cover
Not sure how exposed your store is on PIPEDA?
AtlanticWorks builds privacy-ready Shopify and HubSpot setups for Canadian manufacturers, wholesalers, and DTC brands, including data mapping, consent tracking, and vendor review for the AI agents already running in your stack. The free assessment is the right place to start.
Start the Assessment