Every Canadian dental clinic that collects patient names, phone numbers, appointment records, or health histories must comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). Compliance is built on 10 fair information principles, each carrying specific obligations for your intake forms, recall software, and breach response procedures. This checklist translates those principles into specific actions your practice can complete and verify, with provincial law variations noted for Ontario, Quebec, Alberta, and British Columbia.
Does PIPEDA Apply to Your Dental Practice?
Yes. PIPEDA applies to every private dental practice that collects personal information in the course of commercial activity. The Act received Royal Assent in April 2000 and was extended to cover dental and other health practices by 2004, as confirmed by the Office of the Privacy Commissioner of Canada. The OPC has applied PIPEDA directly to dental offices in formal investigations, confirming that dental health records are classified as sensitive personal information requiring heightened protection.
Seven provinces have enacted legislation that the OPC considers "substantially similar" to PIPEDA: Ontario (PHIPA), Alberta (HIA), British Columbia (PIPA), Quebec (Law 25 / ARPPIPS), New Brunswick (PHIPAA), Newfoundland & Labrador (PHIA), and Nova Scotia (PHIA). In these provinces, provincial law takes precedence for the activities it covers. However, the 10 fair information principles remain the practical compliance framework for all provinces, because every substantially similar law aligns with PIPEDA's core requirements.
In Manitoba, Saskatchewan, and Prince Edward Island, federal PIPEDA applies directly to commercial dental activity without a provincial overlay.
The PIPEDA Dental Practice Compliance Checklist
The following checklist maps each of the 10 PIPEDA fair information principles to a specific action your dental practice must be able to demonstrate. Use it as a self-audit tool: any item you cannot check off represents a compliance gap that needs to be addressed before patient data is collected or processed through new systems.
1
Accountability
Designate a named privacy officer (or compliance manager) in writing. This person handles patient access requests, escalates potential breaches, and keeps your vendor contracts current.
Dental action: Get written confirmation from your recall software, billing system, and patient communication platform that each has a Data Processing Agreement (DPA) on file.
2
Identifying Purposes
State the reason for each piece of data you collect before or at the point of collection. Vague language like 'administrative purposes' does not satisfy this principle.
Dental action: Audit your patient intake form. It must name every specific purpose: appointment scheduling, recall reminders, insurance billing, specialist referral, and public health reporting. Each new purpose needs fresh consent.
3
Consent
Obtain consent appropriate to the sensitivity of the information. Dental health records are classified as sensitive health information under PIPEDA, requiring express (explicit) consent in most cases.
Dental action: Ensure your consent form distinguishes between treatment consent and communication consent. A patient who signs a treatment consent form has not automatically consented to receiving recall SMS messages.
4
Limiting Collection
Collect only the minimum information necessary for the stated purpose. According to the Journal of the Canadian Dental Association, dentists do not need the most intimate details, only what is genuinely pertinent to dental care.
Dental action: Remove any fields from your intake form that your practice cannot directly justify: Social Insurance Numbers should not appear without a specific insurance reason, and questions about unrelated medical conditions should be reviewed by your dentist.
5
Limiting Use, Disclosure, and Retention
Use patient contact data only for the purposes you disclosed. Never share patient lists with third parties without consent. Delete data when it is no longer needed.
Dental action: Confirm your recall software cannot export patient data to third-party marketing lists. Establish a retention schedule: determine how long you keep inactive patient records before securely destroying them.
6
Accuracy
Keep personal information as accurate and up-to-date as needed for its intended purpose. This includes contact details, emergency contacts, and insurance information.
Dental action: Update patient contact details at every appointment, not just at new-patient intake. Inaccurate phone numbers in your recall system are both a PIPEDA compliance issue and a missed recall opportunity.
7
Safeguards
Apply security measures appropriate to the sensitivity of the information. The OPC's safeguards principle requires physical, organisational, and technical protections.
Dental action: Three safeguards the CDA Journal identifies as specific to dental offices: computer screens must not be visible to other patients or to the public; patient health disclosures must not be solicited in waiting rooms or public reception areas; protocols must exist for employer or insurer requests for patient contact information.
8
Openness
Maintain a publicly available privacy policy in plain language and make it available to patients on request. It must cover what you collect, why, how it is stored, and who can access it.
Dental action: Post your privacy policy on your practice website. At minimum, have a printed copy available at reception. A document that patients cannot find does not satisfy the Openness principle even if it is technically excellent.
9
Individual Access
Respond to patient requests to access their personal information within 30 days. The deadline can be extended by an additional 30 days, but only with written notice to the patient explaining the reason.
Dental action: Designate a single point of contact for access requests (this is typically the same person as your privacy officer). Train your front desk to recognise an access request and escalate it on the day it arrives.
10
Challenging Compliance
Provide patients with a clear path to challenge your privacy practices. At minimum, this means a named contact and a written process for lodging a complaint.
Dental action: Include the privacy officer's name or role and a contact email address on your privacy policy. Patients who cannot find a complaint path will file directly with the OPC, triggering a formal investigation.
DentRecall is built PIPEDA-compliant from the ground up
Express SMS consent capture, STOP opt-out handling, and Canadian data storage. Every principle covered from day one.
See How It WorksProvincial Privacy Laws: What Each Province Requires
In provinces with substantially similar legislation, the provincial law governs the collection, use, and disclosure of patient health information. In practice, this means your compliance checklist must satisfy both the provincial standard and PIPEDA's baseline principles. According to Myla Training Corp's analysis of dental privacy regulations, dental practices must also comply with their provincial dental regulatory college's requirements, which may include additional obligations around record retention periods and patient consent processes.
| Province | Primary Law | Key Notes for Dental Practices |
|---|
| Ontario | PHIPA | Personal Health Information Protection Act. Dentists are classified as 'health information custodians' with specific obligations around consent, access, and breach notification. |
| Alberta | HIA | Health Information Act. Governs health information held by custodians. PIPA applies separately to non-health personal information. |
| British Columbia | PIPA | Personal Information Protection Act. Governs all personal information in the course of commercial activity. |
| Quebec | Law 25 / ARPPIPS | Law 25 introduced mandatory Privacy Impact Assessments before adopting new technology, a 5-year breach record retention requirement, and enhanced individual rights. |
| New Brunswick | PHIPAA | Personal Health Information Privacy and Access Act. Governs personal health information. |
| Newfoundland & Labrador | PHIA | Personal Health Information Act. |
| Nova Scotia | PHIA | Personal Health Information Act. |
| Manitoba, Saskatchewan, PEI | PIPEDA (federal) | No substantially similar provincial legislation. Federal PIPEDA applies directly to commercial dental activity in these provinces. |
Quebec: Additional Requirements Under Law 25
Quebec's Law 25 (in force since September 2023) adds three obligations above the PIPEDA baseline: a mandatory Privacy Impact Assessment before adopting any new technology that processes personal information; a five-year breach record retention requirement (compared to PIPEDA's 24 months); and enhanced individual rights including the right to data portability. Any dental practice onboarding a new recall software platform in Quebec must complete a Privacy Impact Assessment before the first patient record is imported.
Mandatory Breach Reporting: Steps Every Dental Practice Must Follow
Since November 1, 2018, PIPEDA requires all organisations, including dental practices, to report any breach of security safeguards that creates a real risk of significant harm to affected individuals. Dental health records are inherently classified as sensitive health information under PIPEDA, which means that almost any breach involving patient data will trigger the real-risk threshold. The steps below are based on the OPC's privacy breach guidance for organisations.
1
Contain the breach
Immediately limit access to the compromised system or data. Disable affected accounts, revoke access tokens, or take affected devices offline as appropriate.
2
Assess the risk of significant harm
Determine whether the breach creates a real risk of significant harm to affected individuals. Factors include: sensitivity of the information (dental health records are inherently sensitive), the probability of misuse, and the number of individuals affected.
3
Report to the OPC
If real risk of significant harm exists, report to the Office of the Privacy Commissioner of Canada as soon as feasible. Use the OPC's online breach reporting portal. There is no defined number of days — the standard is as soon as feasible after the organisation determines a qualifying breach has occurred.
4
Notify affected individuals
Notify the affected patients directly, also as soon as feasible. The notice must describe what happened, what information was involved, what steps the practice is taking, and how the patient can contact the privacy officer for more information.
5
Record the breach
Record every breach of security safeguards in a breach record, regardless of whether it meets the real-risk-of-significant-harm threshold. Records must be kept for a minimum of 24 months under PIPEDA (five years under Quebec's Law 25). The OPC can request these records at any time.
Failure to report a qualifying breach, or failure to maintain breach records, is a specific offence under PIPEDA. As confirmed by section 28 of the PIPEDA legislation, each violation carries a fine of up to $100,000 CAD. The OPC refers matters to the Attorney General of Canada for prosecution. A public finding naming your dental practice remains accessible online indefinitely and can affect patient acquisition.
Four Common PIPEDA Violations in Dental Practices
The following violations appear repeatedly in OPC investigations and enforcement findings against health-sector organisations. Each is preventable with straightforward administrative steps.
No designated privacy officer
The OPC's Accountability principle requires a named individual to be responsible for PIPEDA compliance. Many practices assume the dentist-owner fulfils this role by default. PIPEDA requires a formal designation, meaning someone with clear authority and a documented mandate.
Continuing to send messages after STOP
Once a patient sends STOP, CANCEL, UNSUBSCRIBE, or a similar opt-out keyword, all automated recall and marketing messages must cease immediately. Continuing to send is a violation of both PIPEDA's Consent principle and the Canadian Anti-Spam Legislation (CASL).
No Data Processing Agreement with vendors
Every third party that processes patient personal information on your behalf, including your recall software, billing platform, or email provider, must have a written Data Processing Agreement in place. Without a DPA, you have transferred data to a third party without adequate safeguards, which violates the Accountability and Safeguards principles.
Missing or delayed breach records
Since November 1, 2018, all dental practices must maintain a written record of every breach of security safeguards for at least 24 months, even if the breach does not require reporting to the OPC. Failing to maintain breach records is a specific offence under PIPEDA carrying a fine of up to $100,000 CAD.
Key Takeaways
- PIPEDA applies to all Canadian dental practices collecting personal information in the course of commercial activity. In Ontario, Alberta, BC, Quebec, and four Atlantic provinces, substantially similar provincial legislation takes precedence but aligns with PIPEDA's core principles.
- The 10 PIPEDA fair information principles each require specific actions: designating a named privacy officer (Accountability), stating collection purposes explicitly before intake (Identifying Purposes), obtaining express consent for dental health information (Consent), and responding to access requests within 30 days (Individual Access).
- Mandatory breach reporting has been in force since November 1, 2018. Any breach involving dental health records almost certainly meets the real-risk-of-significant-harm threshold, triggering dual notification to the OPC and affected patients.
- Breach records must be kept for a minimum of 24 months under PIPEDA (five years under Quebec's Law 25), even for incidents that do not require reporting. Failing to maintain records is itself a criminal offence carrying a fine of up to $100,000 CAD.
- The four most preventable violations are: no designated privacy officer, continuing automated messages after a STOP request, using vendors without Data Processing Agreements, and missing or delayed breach records.