Privacy
Available nowPIPEDA · S.C. 2000, c. 5 (current to 2026-06-21)
Canada’s Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), Part 1 and Schedule 1, modeled at the Act’s own clause and subsection level. It binds an organization in respect of personal information it collects, uses or discloses in the course of commercial activities, and in respect of employee and job-applicant information where it operates a federal work, undertaking or business. Three regions are scored: all 56 numbered clauses of Schedule 1 — the ten fair information principles of CAN/CSA-Q830-96 made binding by s.5(1), covering accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access and challenging compliance; the statutory obligations of Division 1 (ss.5-10), including the reasonable-person purpose test, valid consent, the closed lists of collection, use and disclosure without consent, the business-transaction and employment grounds, and the access-request regime with its thirty-day clock, extension notice, refusal grounds and alternative-format duty; and Division 1.1 (ss.10.1-10.3) on breaches of security safeguards — reporting to the Privacy Commissioner of Canada, notifying affected individuals and other organizations, and keeping a record of every breach. The reprisal prohibition at s.27.1(1) is scored as well. Interpretation and definitions, application and transitional provisions, the Canada Evidence Act certificate regime, the remedies, audit and general Divisions addressed to the Commissioner, the courts and Parliament, Part 2 on electronic documents and Schedules 2 to 4 are cited but not scored: they impose no implementable duty on an organization, or they bind someone other than an organization.
104
requirements tracked
Premium
Access
Add-on from $39/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 104 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 104 requirements
- In Keel’s scored scope
- 104 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
What Keel does
How Keel helps with PIPEDA
- Track PIPEDA as a control set with a live readiness score
- Crosswalked to your other frameworks, so shared controls are evidenced once
- Collect evidence in one place and reuse it everywhere
Collect once, comply everywhere
PIPEDA shares canonical controls with GDPR, SOC 2 and HIPAA and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding PIPEDA rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- PCI DSS shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- GDPR shares canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials shares canonical controls
- ISO/IEC 42001 no shared canonical controls
- NIST AI Risk Management Framework no shared canonical controls
- EU AI Act no shared canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline shares canonical controls
A framework is lit when at least one canonical control satisfies both PIPEDA and that framework. Unlit means none of them do — an absence, not a judgment about that standard. 15 of 21 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks