Study Guide

CIPP/C Study Guide: Map the Law Before the Rule

A CIPP/C study approach built on jurisdiction mapping: distinguish PIPEDA, the federal Privacy Act, provincial private-sector acts, Quebec Law 25 and PHIPA.

Updated September 20269 min readStudy GuidePrivacy Cert Prep
Julia Holmes

Julia Holmes

Privacy Cert Prep Editorial Team

Study for the CIPP/C by jurisdiction mapping first: classify each scenario by sector and province, name the governing statute and regulator, then apply that statute's consent and breach rules. Worked scenarios, a comparison table, and a self-check rubric below build that habit.

Solving the first question of every scenario: which law applies

Before any rule, decide sector and geography: private sector in a substantially similar province, federal private sector, federal public sector, Quebec, or a specialized health regime. That decision determines the statute, regulator, and consent standard.

Trace the activity, not the company's label. PIPEDA governs personal information handled in the course of commercial activity at the federal level, while Alberta's and British Columbia's private-sector acts are deemed substantially similar and cover in-province commercial activity. An organization headquartered in a substantially similar province may still have operations, data flows, or transactions that bring PIPEDA back into scope.

Worked scenario: a Calgary online retailer sells to customers across Canada, and a colleague says PIPEDA never applies because Alberta has its own act. The mistake is stopping at the substantially similar label. The better decision: for purely in-province retail activity, Alberta's PIPA governs and the provincial commissioner handles complaints; for the interprovincial sales operation, PIPEDA may govern and the Office of the Privacy Commissioner of Canada becomes relevant. Getting the regulator right shapes every downstream answer.

PIPEDA's consent model: knowledge, meaningfulness, and implied consent

PIPEDA's Schedule 1 fair information principles require meaningful consent, which can be express or implied depending on sensitivity and the reasonable person's expectations. Accountability is the anchoring principle an organization must demonstrate.

Distinguish the two consent forms by context rather than a fixed list. Express consent suits sensitive information or purposes outside what a reasonable person would expect; implied consent can be appropriate for less sensitive information where the purpose is obvious. The knowledge component matters: consent is meaningful only if individuals understand what they are agreeing to, which links consent to the purposes-identification and openness principles.

Apply the model with purpose-exception reasoning. Consent is the default, but PIPEDA recognizes situations where collection, use, or disclosure can proceed without it, such as certain legal-compliance disclosures. Practice explaining why an exception fits: identify the purpose, test it against the reasonable person, and confirm accountability documentation exists. A useful drill: take a marketing program, state the consent type you would choose, the information's sensitivity, and the Schedule 1 principles that constrain it, then swap the information for something more sensitive and redo the analysis.

Why the federal Privacy Act breaks the consent habit you built for PIPEDA

The Privacy Act governs federal government institutions, and consent is not its primary control. Purpose limitation governs: collection must relate to an operating program or activity, and use must stay consistent with the collection purpose.

The conceptual shift is from market consent to administrative necessity. Public institutions collect personal information for program delivery, so the statute constrains collection, retention, and disclosure directly. Individuals instead hold access and correction rights, and the Act pairs with the Access to Information Act in the federal ATIP framework. The Privacy Commissioner investigates complaints and makes findings in an investigative, recommendation-based model rather than issuing binding orders.

Common confusion: applying PIPEDA-style consent analysis to a federal department. Worked scenario: a benefits officer wants to share applicant data with another program to improve service, and a colleague proposes adding a consent checkbox. The better decision: first test the disclosure against the Privacy Act's use and disclosure provisions, because a consent fix cannot legitimize an inconsistent use. Why it matters: the two regimes answer different questions, and borrowing the private-sector tool obscures the actual legal test.

Quebec Law 25: the civil-law regime with its own consent and documentation rules

Quebec's private-sector act, modernized by Law 25, is deemed substantially similar but diverges in practice: consent must be clear, free, and informed, express consent applies in specified circumstances, and documentation duties are prominent.

Three features reward separate study. First, the Commission d'accès à l'information is the regulator, distinct from the federal and common-law-provincial commissioners. Second, the regime leans on proactive instruments: privacy impact assessments for specified projects and transfers, a designated privacy officer, and a register of confidentiality incidents. Third, breach notification follows a risk-of-harm analysis that is worded differently from PIPEDA's real-risk-of-significant-harm test, so do not interchange the two standards.

Worked scenario: a national firm with a Montreal office copies its PIPEDA breach playbook for a Quebec incident, notifying only when the federal significant-harm threshold is met. The mistake is treating one national threshold as universal. The better decision: run the Quebec risk-of-harm analysis, log the incident in the register, and check whether an assessment or express-consent rule applies to the underlying processing. Why it matters: the same incident can demand different documentation and notification decisions in Quebec than elsewhere in Canada.

Health information and the circle of care: PHIPA's different consent logic

Ontario's PHIPA governs health information custodians and is deemed substantially similar for that sector. Its hallmark is implied consent for sharing personal health information within the circle of care for care purposes.

The circle of care is a mental shortcut with edges you must be able to describe: it covers receiving care, not administrative convenience, secondary use, or open-ended disclosure. Custodian status is the entry gate, so distinguishing custodians from agents and from non-custodian recipients is a recurring analytical step. The Information and Privacy Commissioner of Ontario enforces this regime, separate from the federal commissioner.

Practical exercise: build a jurisdiction-mapping table with four profiles — a BC retailer, a federal department, a Montreal fintech, and an Ontario family health practice. For each, write the governing statute, regulator, consent default, and one distinctive feature, then swap profiles into new fact patterns. Self-check rubric: for each profile you should produce all four fields from memory in under a minute, and you should be able to say in one sentence why a neighbouring statute does not govern.

SettingTypical governing statuteRegulatorConsent approachDistinctive feature
Private sector, most provinces or interprovincialPIPEDAOffice of the Privacy Commissioner of CanadaMeaningful consent; express or implied by contextSchedule 1 fair information principles
Private sector, in-province BC or AlbertaProvincial PIPAProvincial commissionerConsent with reasonable-purpose flexibilityDeemed substantially similar to PIPEDA
Private sector, QuebecPrivate-sector act as amended by Law 25Commission d'accès à l'informationClear, free, informed; express in specified casesImpact assessments and incident register
Federal government institutionPrivacy ActPrivacy Commissioner of CanadaPurpose limitation, not market consentPaired with the Access to Information Act
Ontario health custodianPHIPAInformation and Privacy Commissioner of OntarioImplied consent within the circle of care for care purposesCustodian-specific health rules

Breach decisions: running the risk assessment instead of guessing

Breach questions test a documented analysis, not a reflex. Under PIPEDA, report to the regulator and notify individuals where a breach creates a real risk of significant harm, weighing sensitivity and probability of misuse, and record every breach.

Worked scenario: an employee emails a spreadsheet with names, social insurance numbers, and account balances to the wrong internal recipient, who confirms deletion. A colleague says notify everyone immediately; another says skip notification since deletion is confirmed. The better decision: assess sensitivity and probability of misuse, note that SINs raise sensitivity, document the reasoning and outcome either way, and keep the required breach record. A Quebec branch must also apply its own risk-of-harm standard and register entry.

Distinguish the notification decision from the recording duty. Recording applies to all breaches regardless of notification, which makes the breach record itself a compliance artifact worth studying. Practice with three variants — locked laptop, misdirected email, exposed cloud folder — and for each write the sensitivity rating, the misuse-probability reasoning, your notification conclusion, and what your record would show. Self-check rubric: your written reasoning should cite the specific factors, not just the conclusion, and should name the correct regulator for the scenario's jurisdiction.

Enforcement pathways and a preparation sequence that ends in readiness checks

Know who hears what: the federal commissioner investigates PIPEDA and Privacy Act complaints with a recommendation-based model, provincial commissioners handle their acts, and Federal Court review is available after a PIPEDA complaint process.

Trace one complaint end to end: individual complaint, Commissioner investigation, report with findings and recommendations, then the individual's option to apply to the Federal Court for a hearing, where damages may be sought. Canadian case law, notably a leading Federal Court of Appeal decision, has treated PIPEDA as not creating a freestanding cause of action for damages, which is why the complaint pathway precedes court access. Note one administrative point: eligibility, scheduling, and fee details for the credential rest with the IAPP.

An adaptable preparation sequence: week one, map statutes and regulators using the table above; weeks two and three, drill PIPEDA principles and consent reasoning with the marketing drill; week four, Quebec and health divergences; week five, breach variants and the recording duty; final week, full jurisdiction-mapping scenarios from the exercise. Readiness checks: reproduce the comparison table unaided, write the breach reasoning rubric for all three variants, explain the Privacy Act's purpose-limitation logic in one paragraph, and retake the four-profile mapping drill until every field is correct without notes. Self-check scores are learning milestones, not passing predictions.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for Certified Information Privacy Professional / Canada (CIPP/C).

Do I need to memorize every provincial privacy statute for the CIPP/C?
No. Learn the structure: which provinces run substantially similar private-sector acts, which regulator enforces each, and one distinctive feature per regime. Depth belongs with PIPEDA, the federal Privacy Act, Quebec's Law 25 amendments, and Ontario's health regime.
How is the Privacy Act different from PIPEDA in practice?
PIPEDA constrains private-sector commercial activity through meaningful consent plus fair information principles. The Privacy Act constrains federal institutions through purpose limitation on collection and use, and gives individuals access and correction rights, with complaints investigated by the Privacy Commissioner.
Can an individual sue under PIPEDA?
PIPEDA does not itself create a freestanding cause of action for damages, a point established in leading Federal Court of Appeal case law. The route runs through the complaint process: a Commissioner investigation and report, after which the complainant may apply to the Federal Court for a hearing, where damages may be ordered.
Is the Quebec breach threshold the same as PIPEDA's?
Treat them as different standards. PIPEDA uses a real risk of significant harm analysis with factors such as sensitivity and probability of misuse. Quebec's Law 25 regime uses a risk-of-harm analysis and adds documentation duties, including a register of confidentiality incidents.
How do I decide between express and implied consent in a scenario answer?
Start with sensitivity and the reasonable person's expectations. Sensitive information or unexpected purposes point to express consent; low-sensitivity information with an obvious, reasonable purpose can support implied consent. State your reasoning, because the justification is what distinguishes a defensible answer from a guess.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.