Compliance

PIPEDA, meaningful consent, and a deliberately strict default.

Canada’s federal statute allows implied consent for non-sensitive purposes, which makes it more permissive than the EEA on paper. StrongPrivacy still treats a Canadian visitor as opt-in, and this page explains that choice rather than hiding it.

Law
Personal Information Protection and Electronic Documents Act
Detected as
PIPEDA
Regulator
Office of the Privacy Commissioner of Canada
Default model
Opt-in (stricter than the statutory baseline)

What meaningful consent means

PIPEDA’s consent standard is that an individual must be able to understand the nature, purpose and consequences of what they are agreeing to. The Office of the Privacy Commissioner’s Guidelines for obtaining meaningful consent set out what that requires in practice: emphasise what is collected, who it is shared with, what the purposes are and what the residual risk of harm is, and let people control the level of detail they see.

Express consent is expected where the information is sensitive, where the use falls outside the individual’s reasonable expectations, or where the risk of harm is significant. Implied consent is available otherwise. Behavioural advertising has its own long-standing guidance, which treats opt-out as workable only where the individual is made aware of it at or before collection, the mechanism is easy to use and immediately effective, and the data is not sensitive.

Why the default is opt-in anyway

The engine puts PIPEDA in its opt-in set. That is stricter than the statute strictly requires, and it is a deliberate product choice rather than a claim about Canadian law. Three reasons: most properties that reach Canadian visitors also reach European ones and run a single configuration; the boundary between "sensitive" and "not sensitive" is a judgement call the runtime cannot make; and failing closed is recoverable, while a pixel that fired before a choice is not.

You can override it, explicitly

If you have taken advice and concluded that implied consent is appropriate for your Canadian audience, add a region rule for CA with the model you want. Rules are evaluated before the profile, they appear in the published configuration, and the resulting decisions record that they were matched by country rather than by profile.

What each region profile resolves to

Region profileResolved modelWhat the visitor sees
Regional defaultsopt-inNothing optional loads until a choice is made
Global strictopt-inNothing optional loads until a choice is made, everywhere
Global balancedopt-inNothing optional loads until a choice is made
EU and UK opt-innoneNo banner

A visitor in Quebec never reaches this row. CA + QC is tested first and resolves to QC_LAW25, which has its own page.

This is a product reference, not legal advice

It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.

Common questions

Does PIPEDA require a cookie banner?

It requires meaningful consent for collection, use and disclosure, and transparency about purposes. It does not prescribe a banner, and for non-sensitive purposes consent may be implied where the individual is properly informed. A banner remains the most practical way to inform and to record.

Why does StrongPrivacy use opt-in when the law allows opt-out?

Because one configuration usually serves several jurisdictions, and because the engine cannot judge which of your purposes are sensitive. Opt-in is the safe default; a CA region rule is the documented way to choose otherwise.

Does this cover provincial private-sector laws?

Not automatically. Quebec is detected separately. Alberta and British Columbia have substantially similar private-sector laws that generally govern covered intraprovincial processing, while PIPEDA continues to apply in relevant federal, interprovincial and international contexts. The engine currently resolves visitors in Alberta and British Columbia to its PIPEDA product model; that is a configuration shortcut, not a statement that PIPEDA is always the governing statute. Add CA-AB and CA-BC rules where your analysis requires different treatment.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.