Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C.

Apache-2.0Auto-check passedLegal & Compliance

Install Canada Pipeda

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill canada-pipeda -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills canada-pipeda --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/canada-pipeda .claude/skills/canada-pipeda && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canada-pipeda
GitHub stars
301
Token cost
~3.2k tokens
SKILL.md length
1,643 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C.

  • Works in 7 steps: Emphasize key elements — what personal… → Allow individuals to control the level… → Provide clear options: say yes, say no,… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, The 10 Fair Information…, Breach of Security Safeguards… and Cross-Border Transfers, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Canada Pipeda is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair information principles in Schedule 1, consent requirements, cross-border transfer obligations, breach notification under Division 1.1, and OPC enforcement. Keywords: PIPEDA, Canada privacy, fair information principles, OPC, breach notification, cross-border transfer, consent.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the canada-pipeda skill to guide compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C”
  • “/canada-pipeda”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Emphasize key elements — what personal information is collected, with whom it is shared, for what purposes, and the risk of harm
  2. Allow individuals to control the level of detail they receive
  3. Provide clear options: say yes, say no, request changes
  4. Be innovative and creative about consent mechanisms
  5. Consider the consumer's perspective in evaluating consent
  6. Make consent an ongoing process, not a one-time event
  7. Be ready to demonstrate compliance — document consent records

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Canada Pipeda loads about 3.2k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,643 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,643 words, ~3,159 tokens.

Download SKILL.mdSave it as .claude/skills/canada-pipeda/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
canada-pipeda
description
Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair information principles in Schedule 1, consent requirements, cross-border transfer obligations, breach notification under Division 1.1, and OPC enforcement. Keywords: PIPEDA, Canada privacy, fair information principles, OPC, breach notification, cross-border transfer, consent.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
global-privacy-regulations
metadata.tags
pipeda, canada-privacy, fair-information-principles, opc, breach-notification

Canada PIPEDA Compliance

Overview

The Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) is Canada's federal private-sector privacy law. It applies to organizations that collect, use, or disclose personal information in the course of commercial activities, and to personal information about employees of federal works, undertakings, and businesses. PIPEDA incorporates the Canadian Standards Association (CSA) Model Code for the Protection of Personal Information (CAN/CSA-Q830-96) as Schedule 1, establishing 10 fair information principles.

The Office of the Privacy Commissioner of Canada (OPC) oversees PIPEDA compliance, investigates complaints, conducts audits, and publishes findings and guidance. The Digital Privacy Act (S.C. 2015, c. 32) amended PIPEDA to add mandatory breach reporting, valid consent requirements, and enhanced enforcement provisions.

Note: PIPEDA does not apply in provinces that have enacted substantially similar legislation (Alberta PIPA, British Columbia PIPA, Quebec's Act respecting the protection of personal information in the private sector). However, PIPEDA continues to apply to interprovincial and international transfers of personal information in all provinces and to federally regulated organizations.

The 10 Fair Information Principles (Schedule 1)

Principle 1 — Accountability (Clause 4.1)

An organization is responsible for personal information under its control. It must designate an individual or individuals who are accountable for compliance with the principles. Accountability remains with the organization even when personal information is transferred to a third party for processing.

Key requirements:

  • Designate a privacy officer or chief privacy officer
  • Implement policies and practices to give effect to the principles
  • Establish complaint-handling procedures
  • Train staff on privacy obligations
  • Develop information to explain the organization's policies and procedures
Principle 2 — Identifying Purposes (Clause 4.2)

The purposes for which personal information is collected must be identified at or before the time of collection. If a new purpose arises after collection, the organization must identify the new purpose and obtain fresh consent before using the information for that purpose.

The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate (as listed in sections 7(1)-(3) of PIPEDA).

Consent forms recognized by the OPC:

  • Express consent: Required for sensitive information (health data, financial information, precise location, children's data)
  • Implied consent: Acceptable where the purpose would be obvious to a reasonable person and the information is less sensitive
  • Opt-out consent: Acceptable in limited circumstances for non-sensitive information where the individual is notified and given a reasonable opportunity to decline

OPC Guidelines for Obtaining Meaningful Consent (2018):

  1. Emphasize key elements — what personal information is collected, with whom it is shared, for what purposes, and the risk of harm
  2. Allow individuals to control the level of detail they receive
  3. Provide clear options: say yes, say no, request changes
  4. Be innovative and creative about consent mechanisms
  5. Consider the consumer's perspective in evaluating consent
  6. Make consent an ongoing process, not a one-time event
  7. Be ready to demonstrate compliance — document consent records
Principle 4 — Limiting Collection (Clause 4.4)

The collection of personal information shall be limited to that which is necessary for the purposes identified. Information shall be collected by fair and lawful means. An organization must not collect personal information indiscriminately. Each element of personal information collected must be tied to an identified purpose.

Principle 5 — Limiting Use, Disclosure, and Retention (Clause 4.5)

Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes. Organizations must develop guidelines and implement procedures for the retention and destruction of personal information.

Principle 6 — Accuracy (Clause 4.6)

Personal information shall be as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used. The degree of accuracy required depends on the use — information used to make a decision about an individual must be sufficiently accurate to minimize the possibility of an inappropriate decision.

Principle 7 — Safeguards (Clause 4.7)

Personal information shall be protected by security safeguards appropriate to the sensitivity of the information. The level of protection must be commensurate with the sensitivity — more sensitive information requires stronger safeguards.

Categories of safeguards:

  • Physical measures: Locked filing cabinets, restricted access to offices, clean desk policies
  • Organizational measures: Security clearances, need-to-know access, staff training, confidentiality agreements
  • Technological measures: Encryption, passwords, firewalls, audit trails, access controls
Principle 8 — Openness (Clause 4.8)

An organization shall make readily available to individuals specific information about its policies and practices relating to the management of personal information. This includes the name or title and address of the person accountable, how to access personal information, a description of the type of information held, and a general account of its use.

Principle 9 — Individual Access (Clause 4.9)

Upon request, an individual shall be informed of the existence, use, and disclosure of their personal information and shall be given access to that information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.

Response requirements:

  • Respond within 30 days of receiving the request
  • Provide the information at minimal or no cost
  • Provide the information in a generally understandable form
  • If access is denied, provide reasons and inform the individual of available recourse

Permitted grounds for refusing access (Section 9(3)):

  • Information protected by solicitor-client privilege
  • Information generated in the course of a formal dispute resolution process
  • Information that could reasonably be expected to threaten the life or security of another individual
  • Information that would reveal confidential commercial information
  • Information collected for an investigation into a breach of an agreement or law
Principle 10 — Challenging Compliance (Clause 4.10)

An individual shall be able to address a challenge concerning compliance with the above principles to the designated individual or individuals accountable for the organization's compliance. Organizations must have procedures to receive and respond to complaints or inquiries. They must investigate all complaints and take appropriate measures to correct information-handling practices.

Show full SKILL.md (641 more words)Show less

Breach of Security Safeguards (Division 1.1, Sections 10.1-10.3)

Mandatory Breach Reporting (Section 10.1)

An organization must report to the OPC any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm (RROSH) to an individual.

RROSH Assessment Factors

The RROSH assessment must consider:

  • The sensitivity of the personal information involved
  • The probability that the information has been, is being, or will be misused
  • Any other prescribed factor

Significant harm includes: bodily harm, humiliation, damage to reputation, loss of employment, financial loss, identity theft, negative effects on credit record, damage to or loss of property.

Notification Requirements (Section 10.1(3)-(6))

Report to OPC: Must contain:

  • A description of the circumstances of the breach and, if known, the cause
  • The day or period on which the breach occurred
  • A description of the personal information involved
  • The number of individuals affected
  • Steps taken to reduce the risk of harm or to mitigate harm
  • Whether the organization has notified the affected individuals
  • Name and contact information of a person who can answer OPC questions

Notify affected individuals (Section 10.1(4)):

  • As soon as feasible after determination that RROSH exists
  • Must contain: description of the breach, personal information involved, steps taken, steps the individual can take to reduce risk of harm, contact information for further inquiries
  • Must be conspicuous and given directly to the individual (or indirectly if direct notification would cause further harm, or the organization does not have contact information)

Notify other organizations (Section 10.2): If notification to another organization may reduce the risk of harm, notify that organization.

Record-Keeping (Section 10.3)

Organizations must keep and maintain a record of every breach of security safeguards involving personal information under their control for 24 months after the day on which the organization determines that the breach has occurred. The OPC may request access to these records.

Cross-Border Transfers

OPC Position on Transfers

PIPEDA does not prohibit cross-border transfers of personal information. However, the transferring organization remains accountable for the information under Principle 1 (Accountability). The OPC requires:

  1. Comparable protection through contractual or other means
  2. Transparency about cross-border transfers in privacy policies
  3. Notification to individuals that their information may be transferred to foreign jurisdictions and may be accessible to law enforcement of those jurisdictions under lawful authority
  4. Due diligence on the foreign organization's privacy practices
Implications of Foreign Access

Following the OPC findings in PIPEDA Case Summary 2009-008 and the Supreme Court of Canada decision in R. v. Spencer (2014 SCC 43), organizations must consider that personal information transferred to another jurisdiction may be subject to lawful access by foreign governments. This must be communicated to individuals.

Enforcement

OPC Powers
  • Receive and investigate complaints (Section 11-13)
  • Conduct audits (Section 18)
  • Publish findings and recommendations
  • Enter into compliance agreements (Section 17.1)
  • Seek Federal Court orders compelling compliance (Section 14-16)
  • Apply to Federal Court for orders including damages and compliance (Section 16)
Federal Court Remedies (Section 16)

On application by the Commissioner or the complainant, the Federal Court may order an organization to:

  • Correct its practices
  • Publish a notice of action taken
  • Award damages, including damages for humiliation
Penalties (Section 28)

Offences under PIPEDA include:

  • Obstructing the Commissioner or their delegate
  • Destroying personal information that an individual has requested
  • Retaliating against an employee who has filed a PIPEDA complaint
  • Failing to report a breach or maintain breach records (Division 1.1)

Maximum fine: $100,000 CAD per offence (individual) under summary conviction.

Key Regulatory References

  • PIPEDA (S.C. 2000, c. 5)
  • Digital Privacy Act (S.C. 2015, c. 32)
  • Breach of Security Safeguards Regulations (SOR/2018-64)
  • OPC Guidelines for Obtaining Meaningful Consent (2018)
  • OPC Guidelines on Privacy and Online Behavioural Advertising (2023 update)
  • OPC Position on Cross-Border Transfer of Personal Information (PIPEDA Interpretation Bulletin)
  • CSA Model Code CAN/CSA-Q830-96 (Schedule 1 to PIPEDA)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/canada-pipeda of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Canada Pipeda next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canada Pipeda compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canada Pipeda this skillmukul975/Privacy-Data-Protection-Skills301—~3.2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Canada Pipeda

What does Canada Pipeda do?

Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. Canada Pipeda is an agent skill from mukul975/Privacy-Data-Protection-Skills.C.

When should I use Canada Pipeda?

Canada Pipeda fits situations like: tasks that involve Privacy and GDPR.

How do I install Canada Pipeda in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill canada-pipeda -a claude-code`. Or copy the skill folder (skills/privacy/canada-pipeda in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/canada-pipeda in your project. Claude Code loads it when a task matches its description.

How do I install Canada Pipeda in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill canada-pipeda -a codex`. Or copy the skill folder (skills/privacy/canada-pipeda in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/canada-pipeda in your project. Codex loads it when a task matches its description.

Can I use Canada Pipeda in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill canada-pipeda -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canada-pipeda, .gemini/skills/canada-pipeda, .github/skills/canada-pipeda and .opencode/skills/canada-pipeda in your project.

What does Canada Pipeda need to run?

Going by SKILL.md and its folder, Canada Pipeda needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Canada Pipeda access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Canada Pipeda safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Canada Pipeda use?

Canada Pipeda is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canada Pipeda use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Canada Pipeda?

Skills that share tags, products or a category with Canada Pipeda: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canada Pipeda?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.