Mmcp.market

canada-pipeda skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Guides compliance with Canada''s Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair information principles in Schedule 1, consent requirements, cross-border transfer obligations, breach notification under Division 1.1, and OPC enforcement. Keywords: PIPEDA, Canada privacy, fair information principles, OPC, breach notification, cross-border transfer, consent.

A100/100content scan

Is the canada-pipeda skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the canada-pipeda skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/ca/data-protection/skills/canada-pipeda ~/.claude/skills/canada-pipeda
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Canada PIPEDA Compliance

Overview

The Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) is Canada's federal private-sector privacy law. It applies to organizations that collect, use, or disclose personal information in the course of commercial activities, and to personal information about employees of federal works, undertakings, and businesses. PIPEDA incorporates the Canadian Standards Association (CSA) Model Code for the Protection of Personal Information (CAN/CSA-Q830-96) as Schedule 1, establishing 10 fair information principles.

The Office of the Privacy Commissioner of Canada (OPC) oversees PIPEDA compliance, investigates complaints, conducts audits, and publishes findings and guidance. The Digital Privacy Act (S.C. 2015, c. 32) amended PIPEDA to add mandatory breach reporting, valid consent requirements, and enhanced enforcement provisions.

Note: PIPEDA does not apply in provinces that have enacted substantially similar legislation (Alberta PIPA, British Columbia PIPA, Quebec's Act respecting the protection of personal information in the private sector). However, PIPEDA continues to apply to interprovincial and international transfers of personal information in all provinces and to federally regulated organizations.

The 10 Fair Information Principles (Schedule 1)

Principle 1 — Accountability (Clause 4.1)

An organization is responsible for personal information under its control. It must designate an individual or individuals who are accountable for compliance with the principles. Accountability remains with the organization even when personal information is transferred to a third party for processing.

Key requirements:

  • Designate a privacy officer or chief privacy officer
  • Implement policies and practices to give effect to the principles
  • Establish complaint-handling procedures
  • Train staff on privacy obligations
  • Develop information to explain the organization's policies and procedures

Principle 2 — Identifying Purposes (Clause 4.2)

The purposes for which personal information is collected must be identified at or before the time of collection. If a new purpose arises after collection, the organization must identify the new purpose and obtain fresh consent before using the information for that purpose.

Principle 3 — Consent (Clause 4.3)

The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate (as listed in sections 7(1)-(3) of PIPEDA).

Consent forms recognized by the OPC:

  • Express consent: Required for sensitive information (health data, financial information, precise location, children's data)
  • Implied consent: Acceptable where the purpose would be obvious to a reasonable person and the information is less sensitive
  • Opt-out consent: Acceptable in limited circumstances for non-sensitive information where the individual is notified and given a reasonable opportunity to decline

OPC Guidelines for Obtaining Meaningful Consent (2018):

  1. Emphasize key elements — what personal information is collected, with whom it is shared, for what purposes, and the risk of harm
  2. Allow individuals to control the level of detail they receive
  3. Provide clear options: say yes, say no, request changes
  4. Be innovative and creative about consent mechanisms
  5. Consider the consumer's perspective in evaluating consent
  6. Make consent an ongoing process, not a one-time event
  7. Be ready to demonstrate compliance — document consent records

Principle 4 — Limiting Collection (Clause 4.4)

The collection of personal information shall be limited to that which is necessary for the purposes identified. Information shall be collected by fair and lawful means. An organization must not collect personal information indiscriminately. Each element of personal information collected must be tied to an identified purpose.

Principle 5 — Limiting Use, Disclosure, and Retention (Clause 4.5)

Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes. Organizations must develop guidelines and implement procedures for the retention and destruction of personal information.

Principle 6 — Accuracy (Clause 4.6)

Personal information shall be as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used. The degree of accuracy required depends on the use — information used to make a decision about an individual must be sufficiently accurate to minimize the possibility of an inappropriate decision.

Principle 7 — Safeguards (Clause 4.7)

Personal information shall be protected by security safeguards appropriate to the sensitivity of the information. The level of protection must be commensurate with the sensitivity — more sensitive information requires stronger safeguards.

Categories of safeguards:

  • Physical measures: Locked filing cabinets, restricted access to offices, clean desk policies
  • Organizational measures: Security clearances, need-to-know access, staff training, confidentiality agreements
  • Technological measures: Encryption, passwords, firewalls, audit trails, access controls

Principle 8 — Openness (Clause 4.8)

An organization shall make readily available to individuals specific information about its policies and practices relating to the management of personal information. This includes the name or title and address of the person accountable, how to access personal information, a description of the type of information held, and a general account of its use.

Principle 9 — Individual Access (Clause 4.9)

Upon request, an individual shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.

Response requirements:

  • Respond within 30 days of receiving the request
  • Provide the information at minimal or no cost
  • Provide the information in a generally understandable form
  • If access is denied, provide reasons and inform the individual of available recourse

Permitted grounds for refusing access (Section 9(3)):

  • Information protected by solicitor-client privilege
  • Information generated in the course of a formal dispute resolution process
  • Information that could reasonably be expected to threaten the life or security of another individual
  • Information that would reveal confidential commercial information
  • Information collected for an investigation into a breach of an agreement or law

Principle 10 — Challenging Compliance (Clause 4.10)

An individual shall be able to address a challenge concerning compliance with the above principles to the designated individual or individuals accountable for the organization's compliance. Organizations must have procedures to receive and respond to complaints or inquiries. They must investigate all complaints and take appropriate measures to correct information-handling practices.

Breach of Security Safeguards (Division 1.1, Sections 10.1-10.3)

Mandatory Breach Reporting (Section 10.1)

An organization must report to the OPC any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm (RROSH) to an individual.

RROSH Assessment Factors

The RROSH assessment must consider:

  • The sensitivity of the personal information involved
  • The probability that the information has been, is being, or will be misused
  • Any other prescribed factor

Significant harm includes: bodily harm, humiliation, damage to reputation, loss of employment, financial loss, identity theft, negative effects on credit record, damage to or loss of property.

Notification Requirements (Section 10.1(3)-(6))

Report to OPC: Must contain:

  • A description of the circumstances of the breach and, if known, the cause
  • The day or period on which the breach occurred
  • A description of the personal information involved
  • The number of individuals affected
  • Steps taken to reduce the risk of harm or to mitigate harm
  • Whether the organization has notified the affected individuals
  • Name and contact information of a person who can answer OPC questions

Notify affected individuals (Section 10.1(4)):

  • As soon as feasible after determination that RROSH exists
  • Must contain: description of the breach, personal information involved, steps taken, steps the individual can take to reduce risk of harm, contact information for further inquiries
  • Must be conspicuous and given directly to the individual (or indirectly if direct notification would cause further harm, or the organization does not have contact information)

Notify other organizations (Section 10.2): If notification to another organization may reduce the risk of harm, notify that organization.

Record-Keeping (Section 10.3)

Organizations must keep and maintain a record of every breach of security safeguards involving personal information under their control for 24 months after the day on which the organization determines that the breach has occurred. The OPC may request access to these records.

Cross-Border Transfers

OPC Position on Transfers

PIPEDA does not prohibit cross-border transfers of personal information. However, the transferring organization remains accountable for the information under Principle 1 (Accountability). The OPC requires:

  1. Comparable protection through contractual or other means
  2. Transparency about cross-border transfers in privacy policies
  3. Notification to individuals that their information may be transferred to foreign jurisdictions and may be accessible to law enforcement of those jurisdictions under lawful authority
  4. Due diligence on the foreign organization's privacy practices

Implications of Foreign Access

Following the OPC findings in PIPEDA Case Summary 2009-008 and the Supreme Court of Canada decision in R. v. Spencer (2014 SCC 43), organizations must consider that personal information transferred to another jurisdiction may be subject to lawful access by foreign governments. This must be communicated to individuals.

Enforcement

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers