Home / Blog / GDPR vs CCPA vs PIPEDA
Compliance

GDPR vs CCPA vs PIPEDA: A Plain-English Comparison

If you run a business in Canada and sell to anyone beyond your own border, three privacy laws end up mattering: Canada's own PIPEDA, California's CCPA, and the EU's GDPR. They chase the same goal, protecting people's personal information, but they start from different defaults. Get the defaults right and the rest is mostly paperwork.

MH By MarketingHub Editorial · April 26, 2024 · updated September 2026 · 11 min read · Compliance
€20Mor 4% of global revenue: the top GDPR fine
$25M+revenue is one trigger that brings CCPA into play
10fair information principles at the heart of PIPEDA

The three laws in plain English

Before comparing them, it helps to know what each one actually is, without the legalese.

GDPR is the European Union's General Data Protection Regulation, in force since 2018. Its reach is what surprises people: it applies to any organisation, anywhere in the world, that handles the personal data of someone in the EU. You do not need an office in Europe. If you are selling to, or tracking, people who are there, you are in scope. Its starting assumption is simple. The data belongs to the person, and you need a lawful reason, usually their clear consent, to use it.

CCPA, as amended by the CPRA, is California's privacy law. It is enforced by the California Privacy Protection Agency, and it applies to for-profit businesses that do business in California and cross one of a few size thresholds. It hands California residents the rights to know, delete, correct, and opt out of the sale or sharing of their information. Unlike GDPR, it assumes you may collect data unless the person tells you to stop.

PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada's federal private-sector privacy law. It governs businesses that collect, use, or disclose personal information in the course of commercial activity. It is built on ten fair information principles, and its consent model is described as meaningful: the person has to genuinely understand what they are agreeing to. In practice it lands between GDPR and CCPA in strictness.

The one difference that matters most: opt-in vs opt-out

If you remember nothing else, remember this. The three laws disagree about the default answer to "may I use this person's data?"

GDPR says no by default. You need a lawful basis first, and where that basis is consent, it has to be freely given, specific, informed, and unambiguous. A pre-ticked box does not count. CCPA says yes by default. You can collect and use personal information, and the consumer's power is the right to opt out, most visibly through a "Do Not Sell or Share My Personal Information" link. PIPEDA lands in between: you generally need consent, but for less sensitive information that consent can often be implied rather than expressly ticked, as long as it is genuinely meaningful and the person could reasonably expect it.

That single design choice ripples into everything else, from how you build your signup forms to how you handle cookies.

Who each law actually covers

GDPR has no business-size threshold. A two-person shop that sells a digital product to someone in Germany is in scope. CCPA is the opposite: it only applies to a for-profit business that does business in California and meets at least one threshold, roughly $25 million in annual revenue, or buying, selling, or sharing the personal information of 100,000 or more California residents or households a year, or making half or more of its revenue from selling or sharing that information. PIPEDA applies broadly to commercial activity in Canada, with no headcount cutoff, though some provinces (British Columbia, Alberta, and Quebec) have their own laws that stand in for it for activity inside the province.

One provincial law deserves a special flag: Quebec's Law 25. If you handle the personal information of anyone in Quebec, its requirements can be stricter than PIPEDA on consent, transparency, and breach handling, and it carries real penalties. Do not assume "PIPEDA covers me" if you have Quebec customers.

For operators serious about results

Free Compliance Health Check

Get a confidential 30-minute review of your privacy and compliance posture, no obligation.

What rights people get

All three give people the right to see the data you hold, have mistakes corrected, and have their data deleted. The differences are at the edges. GDPR adds the right to data portability, the right to object to certain processing, and protections around decisions made purely by automated systems. CCPA/CPRA closed much of that gap and layered on newer duties around automated decision-making technology, with businesses expected to give notice and an opt-out as those rules phase in. PIPEDA covers access and correction, and a data-portability right was written into it in 2026, though that right is not yet switched on and waits on regulations to make it work.

What happens if you get it wrong

This is where the gap is widest. A serious GDPR breach can cost up to 20 million euros or 4% of your worldwide annual revenue, whichever is higher. That is designed to be existential for a large company. CCPA penalties are smaller per incident, in the low thousands of dollars per violation, but they add up fast across thousands of records, and California has been actively enforcing the opt-out rules with multi-million-dollar settlements. PIPEDA has historically been the gentlest on paper, leaning on investigations and public findings by the Office of the Privacy Commissioner rather than large direct fines, which is one of the main reasons Canada keeps trying to modernise it.

Is PIPEDA about to change?

Worth knowing, because it affects how you plan. Canada has tried three times since 2020 to replace or overhaul PIPEDA: Bill C-11, then Bill C-27, and most recently Bill C-36, introduced in 2026. Each attempt has aimed to give the Privacy Commissioner real order-making and fining power and to modernise consent. As things stand in 2026, none of them has become law, so PIPEDA in its current form is still the rule. The sensible read: build to PIPEDA and Quebec's Law 25 today, keep an eye on the next bill, and know that whatever passes is very likely to move Canada closer to the GDPR end of the scale, not away from it.

Cross-border data, and Canada's quiet advantage

GDPR restricts sending EU personal data to countries it does not consider adequately protective. Canada's commercial sector sits on the EU's adequacy list, which makes moving EU data to a Canadian business far simpler than it is for many other countries. CCPA does not add geographic transfer restrictions of its own. For a Canadian company with European ambitions, that adequacy status is a genuine head start worth protecting.

So what should a Canadian business actually do?

Start from your reality. If you sell only in Canada and the US, treat PIPEDA (and Law 25 if you touch Quebec) as your floor, and check whether you cross any CCPA threshold. If you sell into Europe, or you are growing toward it, build to GDPR from the start, because retrofitting consent later is painful. Either way, the practical baseline is the same three habits: ask for consent clearly and record it, write down why you collect each piece of data and delete it when that reason is gone, and make it genuinely easy for someone to see, correct, or remove what you hold on them.

Privacy law around the world keeps drifting toward the same place: opt-in by default, real rights for the individual, real consequences for ignoring them. A Canadian business that adopts GDPR-grade habits now is not just covered, it earns the trust that quietly wins customers.

MH
MarketingHub Editorial Team Senior strategists, designers and engineers working across SEO, growth, design, AI and compliance for Canadian and international brands. Meet the team →

Frequently asked questions

Quick answers to common questions on this topic. Have a specific situation? Talk to our team.

Does a Canadian small business have to follow GDPR?

Only if you handle the personal data of people who are in the EU, for example by selling to them or tracking them online. GDPR has no size threshold, so a small Canadian shop selling into Europe is in scope, while one selling only within Canada and the US usually is not.

Is PIPEDA still the law in Canada, or has it been replaced?

As of 2026, PIPEDA is still Canada's federal private-sector privacy law. Parliament has tried three times to replace it, most recently with Bill C-36, but none of those bills has passed. Build to PIPEDA today and watch for a successor that is likely to be stricter.

What is the real difference between opt-in and opt-out?

Opt-in (GDPR) means you cannot use someone's data until they clearly agree. Opt-out (CCPA) means you can use it until they tell you to stop. PIPEDA sits between the two, requiring meaningful consent that can sometimes be implied for less sensitive information.

I have customers in Quebec. Does that change anything?

Yes. Quebec's Law 25 can be stricter than PIPEDA on consent, transparency, and breach handling, and it carries real penalties. If you handle the data of anyone in Quebec, treat Law 25 as a separate requirement rather than assuming PIPEDA covers you.

Get expert help

Ready to put this into practice?

Tell us about your business and we will scope a starter engagement or recommend a better starting point, typically within one business day. No obligation, no high-pressure sales call.

Free 30-min consult Canada, US & worldwide Rated 5.0 on Google
RELATED SERVICES: IT & Marketing ConsultationWeb & App Development