jurisdictions in the Canada operating view
Federal · 10 provinces · 3 territoriesKestryl · Cockpit for Canada · Executive Whitepaper
Fourteen jurisdictions. One evidence view.
A brief for Canadian CISOs, CTOs, CIOs and General Counsel on navigating PIPEDA, Quebec Law 25, Alberta and British Columbia private-sector privacy requirements, and provincial public-sector and health-information obligations — what Kestryl can evidence, where it stops, and what pending federal reform could change.
EXECUTIVE WHITEPAPER · SEPTEMBER 2026 · ENGLISH EDITION · NOT LEGAL ADVICE
In brief
Six things a board needs on one page.
-
01
Not one law — three context lenses
Sector, jurisdiction and data context shape the configured operating association. Alberta, British Columbia and Quebec have substantially similar private-sector regimes that may apply instead of PIPEDA in some circumstances, while public-sector and health-information statutes add other jurisdiction-specific requirements. Applicability remains fact-specific and with customer counsel.
-
02
Where the exposure actually sits
Personal information can exist across CRM, ERP, HR, collaboration and document platforms, as well as known downstream-copy locations. The operating view makes declared systems, records, attachments and copies visible without claiming complete enterprise lineage.
-
03
What the cockpit does
Kestryl supports configured jurisdiction context, discovery, incident and transfer records, known-copy follow-through and reviewable evidence. People retain legal judgment, ownership, approval and acceptance of evidence.
-
04
The eight obligation lenses
The eight lenses organize the whitepaper evidence framework across accountability, access, breaches, transfers, consent, retention, safeguards and findings. They describe evidence questions and operating responsibility; they are not legal certifications.
-
05
Bill C-36 — pending reform
Bill C-36 was introduced on June 15, 2026 and is currently at second reading in the House of Commons. Proposed requirements remain separate from current law.
-
06
Where the cockpit stops
The operating model names boundaries for consent, legal judgment, anonymization, known-copy completeness, source-system action and language. Scope and statutory decisions remain with the customer and counsel.
Evidence figures
Four reference points for the executive conversation.
PIPEDA access-response period
PIPEDA s.8(3); specified extensions may apply under s.8(4)Federal breach-record retention
Breach of Security Safeguards Regulations s.6Quebec enforcement ceilings
Contents
Eight sections. One operating question.
Where is personal information, why is it held, where has it travelled, and what evidence exists for the decision taken?
Not one law — three context lenses
Sector, jurisdiction and data context shape the configured operating association.
Where the exposure actually sits
CRM, ERP, HR, claims, collaboration platforms, documents and known downstream copies can all carry personal information.
What the cockpit does in the language of the boardroom
A governed evidence view, configured jurisdiction context, incident and transfer records, ownership and reviewable evidence.
The eight obligation lenses, stated precisely
A whitepaper framework for organizing technical evidence and program responsibilities.
What Bill C-36 could change
Pending federal reform shown separately from current requirements.
Where the cockpit stops
Legal judgment, consent, anonymization, known-copy completeness, source-system action, pending law and language.
White Glove delivery model
Installation, configuration and scheduled Kestryl operations, with scope and cadence defined in the applicable order form.
How an engagement runs
Profile, discover, review, resolve, approve, evidence and expand.
Section 4 · In full
The eight obligation lenses, stated precisely.
Eight lenses organize the whitepaper’s privacy-evidence framework. They are distinct from the ten Privacy Control Outcomes used elsewhere across the Canada service and product pages. A lens describes the evidence question and operating responsibility; it is not a legal certification.
| Lens | Status | What that means in practice |
|---|---|---|
| 1 · Accountability and designated person | Cockpit contributes | Record the accountable role and associate it with the relevant response, matter or evidence package. Responsibility remains with the organization. |
| 2 · Access, correction and portability | Evidenced from configured scope |
Locate relevant records and known copies against the configured response period.
PIPEDA
30 days
Alberta PIPA
45 calendar days
Quebec
30 days
BC PIPA
30 business days
Extensions, exceptions and applicability remain subject to the governing statute and customer/counsel review. |
| 3 · Breach: risk decision and record | Evidenced from configured scope | Organize affected records, categories and known locations; record the customer’s or counsel’s risk/reportability decision and supporting scope. Under PIPEDA’s Breach of Security Safeguards Regulations, organizations must maintain a record of every breach for 24 months after determining that the breach occurred. |
| 4 · Cross-border transfer and PIA | Evidenced from configured scope | Record declared copy locations, processors and associated transfer evidence. For Quebec private-sector data, s.17 requires a privacy impact assessment before personal information is communicated outside Quebec. |
| 5 · Meaningful consent and withdrawal | Cockpit contributes | Locate configured consent-related fields and follow recorded withdrawal signals into known copies. Consent itself is designed, captured and maintained in customer systems. |
| 6 · Retention, destruction and anonymization | Cockpit contributes | Associate assets with an approved disposition and supporting evidence. Quebec s.23 provides that, once the purposes for which personal information was collected or used are achieved, the enterprise must destroy the information or anonymize it for serious and legitimate purposes, subject to applicable preservation requirements. Whether an actual treatment satisfies that legal standard remains with the customer and counsel. |
| 7 · Safeguards and audit trail | Evidenced from configured scope | Record supported approved actions and their review history for structured working data in scope. |
| 8 · Findings, orders and agreements | Cockpit contributes | Associate matters and obligations with owners, terms, due actions and supporting evidence. |
“Evidenced from configured scope” means technical evidence is available within the agreed deployment scope for customer and counsel review. It is not a statement that a legal obligation has been satisfied.
Section 5 · Pending federal reform
PENDING FEDERAL REFORM · AT SECOND READING · NOT CURRENT LAW
What Bill C-36 could change — and what remains current today.
Bill C-36, the Protecting Privacy and Consumer Data Act proposal, received first reading on June 15, 2026. Parliament’s LEGISinfo currently lists the bill at second reading in the House of Commons.
Displayed, not applied
Bill C-36 may be represented as pending context in the operating view, but proposed requirements must not drive current statutory deadlines, statuses or compliance determinations.
The proposal raises the enforcement stakes
The first-reading text proposes higher maximum penalties than current federal private-sector law.
The evidence foundation remains useful
Inventory, access-response evidence, incident records, purpose, retention and decision history are already operating questions under current privacy regimes. Building reviewable evidence now does not require predicting whether or when Bill C-36 becomes law.
The first-reading bill also contains a private right of action and provides for a Digital Safety and Data Protection Commission of Canada framework. These are proposed, not current powers or institutions operating under the proposed Act.
Section 6 · In full
Where the cockpit stops.
| Boundary | What is true today |
|---|---|
| Real-risk / reportability assessment | The cockpit records the customer’s or counsel’s decision, timestamp and supporting scope. It does not make the legal determination and does not send regulator or individual notices. |
| Consent | The cockpit does not obtain consent. It can locate configured consent-related fields and follow recorded withdrawal signals within the agreed scope. Meaningful consent remains the responsibility of customer systems and processes. |
| Anonymization | Kestryl does not determine that information is legally anonymized. Quebec s.23 sets the statutory standard. Whether an outcome meets that standard remains with the customer and counsel. |
| Known copies | Downstream relationships are customer-declared or imported from an available catalog. An undeclared copy is outside the operating register. |
| Source-system action | Approved supported Kestryl actions operate within the current approved product scope. Changes to source systems are separately executed and verified through the operating workflow. |
| Bill C-36 PENDING | Displayed as pending context and not applied as current law. |
| Statutory parameters | Configured statutory parameters are subject to source validation and customer/counsel approval before being relied upon for legal workflow decisions. |
| Language ENGLISH EDITION | English edition. French-language product screens and documentation are not represented as currently delivered. |
A useful compliance operating model names its boundaries before an engagement begins. Scope, legal ownership, source-system authority and evidence limits should be visible rather than implied.
Sources
Primary sources used for the current-law reference points.
- Justice Laws Personal Information Protection and Electronic Documents Act s.8
- Justice Laws Breach of Security Safeguards Regulations s.6
- Légis Québec Private-sector Act ss.3.8, 17, 23, 32, 90.12, 91
- Alberta OIPC PIPA access guidance Access-response guidance
- BC OIPC PIPA access guidance Access and review guidance
- Office of the Privacy Commissioner of Canada Provincial laws that may apply instead of PIPEDA Substantially similar provincial regimes
- Parliament of Canada Bill C-36 · LEGISinfo 45-1 · Second reading
- Parliament of Canada Bill C-36 · First-reading text Proposed legislation
Evidence reviewed: September 19, 2026. This material supports privacy-program and technical-evidence discussions and is not legal advice. Applicability remains fact-specific and should be confirmed with counsel.
Get the executive whitepaper
Put your systems and Canadian jurisdictions into one evidence conversation.
Request the Kestryl Cockpit for Canada executive whitepaper or schedule a briefing to discuss your source systems, jurisdiction context, known copies and evidence requirements.