Privacy & Compliance

Canadian Privacy Laws (Part 2): Ontario Privacy Laws

Ontario privacy law can feel a bit different from the federal privacy laws we covered in part one.

That is because Ontario does not have one broad private-sector privacy law that replaces PIPEDA for most businesses. Instead, Ontario’s privacy rules mostly focus on two areas:

  • public-sector organizations
  • health care and personal health information

So, if you run a typical private business in Ontario, PIPEDA is usually still the main privacy law to know. But Ontario’s provincial laws can still matter if you work with government, municipalities, schools, hospitals, clinics, or health-related data.

Here are the Main Ontario Privacy Laws to Understand

FIPPA: Ontario’s Provincial Public-Sector Privacy Law

The Freedom of Information and Protection of Privacy Act (FIPPA) applies to Ontario’s provincial public sector.

Who it applies to: provincial ministries, many agencies, boards and commissions, colleges, universities, and hospitals.

What it does: FIPPA sets rules for how these organizations collect, use, share, keep, and protect personal information. It also gives people the right to ask for access to information held by these institutions, including their own personal information.

Why businesses should care: If your company works with Ontario public-sector clients, FIPPA may influence what those clients expect from you. This could show up in contracts, security requirements, data handling rules, or procurement questions.

MFIPPA: Privacy Rules for Municipal Organizations

The Municipal Freedom of Information and Protection of Privacy Act (MFIPPA) is similar to FIPPA, but for local government.

Who it applies to: municipalities, school boards, police services boards, and public library boards.

What it does: MFIPPA sets rules for how municipal organizations handle personal information. It also gives people the right to request access to municipal records and to their own personal information.

Why businesses should care: If you work with municipalities, school boards, libraries, or local government organizations, you may need to meet privacy and records-related expectations connected to MFIPPA.

PHIPA: Ontario’s Health Privacy Law

The Personal Health Information Protection Act (PHIPA) is Ontario’s health privacy law.

Who it applies to: health information custodians, such as health care providers, hospitals, pharmacies, laboratories, long-term care homes, ambulance services, and other health organizations.

What it does: PHIPA sets rules for collecting, using, and sharing personal health information. It also gives people the right to access their health information and ask for corrections in certain situations.

Why businesses should care: Health information is highly sensitive. If your business supports health care providers, manages health-related systems, or handles personal health information, PHIPA may affect your privacy, consent, security, and breach response responsibilities.

Quick Comparison

Ontario Law Main Focus Who It Mainly Applies To
FIPPA Provincial public-sector privacy Ministries, agencies, colleges, universities, hospitals
MFIPPA Municipal public-sector privacy Municipalities, school boards, police boards, public libraries
PHIPA Health privacy Health care providers and organizations handling health information

How Ontario Fits with PIPEDA

For many Ontario businesses, PIPEDA still does the heavy lifting when it comes to personal information used in commercial activities. Ontario’s provincial laws usually become more relevant when:

  • you work with a public-sector client
  • you support a municipality or school board
  • you handle personal health information
  • you provide technology, security, cloud, or data services to regulated organizations

Why This Matters for Your Business

Ontario privacy compliance is not only about asking, “Does PIPEDA apply?”

It is also about asking:

  • What kind of data are we handling?
  • Who are we handling it for?
  • Is the client in government, education, health care, or another regulated sector?
  • Are there extra privacy or security expectations in the contract?

Even if your business is not directly covered by FIPPA, MFIPPA, or PHIPA, your clients may be. That means their obligations can become your expectations.

A good starting point is to:

  • know what personal information you collect
  • understand where it is stored
  • limit access to the people who need it
  • document your privacy and security practices
  • be ready to respond if something goes wrong

In short: Ontario may not have one single private-sector privacy law, but its public-sector and health privacy rules still matter, especially for businesses that support government, education, health care, or regulated clients.

A Seven Part Series on Privacy Laws in Canada

Stay tuned for the next entry in our series, where we will look at how privacy laws differ across the Canadian provinces.

  • Part 1: Federal Laws: Unpack overarching federal frameworks like PIPEDA to establish baseline data protection standards.
  • Part 2: Provincial Laws – Ontario: Navigate local corporate privacy standards and sector-specific regulations unique to Ontario.
  • Part 3: Provincial Laws – British Columbia: Examine B.C.’s distinct statutes and strict regional rules regarding data residency.
  • Part 4: Provincial Laws – Alberta: Review Alberta’s PIPA framework for private sector accountability and local consent rules.
  • Part 5: Provincial Laws – Nova Scotia: Learn how Nova Scotia’s regional frameworks shape commercial privacy and administrative accountability.
  • Part 6: Provincial Laws – Quebec: Dive into Quebec’s Law 25, focusing on strict corporate transparency and severe penalties.
  • Part 7: Provincial Laws – Manitoba: Map out Manitoba’s legislative landscape to keep regional digital operations compliant.