What counts as personal information under PIPEDA that my Ontario business needs to protect?
Under PIPEDA, personal information is defined broadly as information about an identifiable individual — meaning it can reasonably be linked back to a specific person, whether alone or combined with other information a business has or can access. That covers obvious categories like a customer's name, address, phone number, and email, but it also extends to things like purchase history, payment details, account activity, and in some contexts, information like an IP address, if it can realistically be tied to a particular individual.
A narrower carve-out exists for basic business contact information, such as an employee's name, title, and work phone number, used specifically to contact that person in their professional capacity, which is treated differently from personal information collected about someone as a customer or private individual. This distinction trips businesses up when they assume all information tied to a person's business role is automatically outside PIPEDA's scope, when the analysis really depends on the purpose the information is being used for.
Because the definition is broad and purpose-driven rather than a short fixed list, Ontario businesses should assume most identifiable customer data falls within it, and build their handling practices, consent, and safeguards around that assumption rather than trying to categorize information as exempt.
Key takeaways
- Personal information under PIPEDA is broadly defined as anything reasonably linked to an identifiable individual.
- It covers contact details, purchase history, payment information, and similar identifiable data.
- A narrow exception exists for business contact information used strictly in a professional capacity.
- Assume most identifiable customer data is covered rather than looking for exemptions.