PIPEDA vs PHIPA and Which Law Governs Your Data Destruction Obligations

By electronic recycling association August 2, 2026

Why the Wrong Law Assumption Creates a Real Compliance Gap

When a batch of retired hard drives is sitting on a cart in the server room, the compliance question is immediate. Someone has to decide what documentation to create, how long to keep it, and which regulator could come asking for it. The trouble is that many Canadian organizations assume a single privacy law covers everything they do with personal information, and that assumption breaks down quickly once health data, provincial jurisdiction, and organizational type enter the picture.

The core question of PIPEDA vs PHIPA is which law actually governs the data on those drives, because the answer determines the standard of destruction, the records you need to retain, and the enforcement body that reviews your work. Getting that threshold question wrong leaves an organization holding destruction records that satisfy the wrong regulator, which is functionally the same as holding no records at all.

The Comparison Criteria That Actually Matter at Retirement Time

General privacy law comparisons tend to focus on consent models, breach notification timelines, and data collection principles. Those matter, but they aren’t what an IT manager or privacy officer is weighing when drives are ready to leave the building. At device retirement, four criteria do the real work:

  • Scope of covered organizations: which entities fall under each law
  • Definition of covered data: what counts as protected information on a drive
  • Destruction and retention obligations: what each law requires when data reaches end of life
  • Documentation and audit requirements: what records survive the drive itself

These four criteria track the decisions that actually get made during device retirement. The differences between the two laws show up most clearly at the moment data leaves an organization’s control.

PIPEDA Scope and What It Demands When Devices Leave

The Personal Information Protection and Electronic Documents Act is federal legislation. It applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity, and it applies to all federally regulated industries regardless of province. If an organization operates commercially in a province that hasn’t enacted its own substantially similar privacy legislation, PIPEDA is the default.

The definition of covered data is broad. Personal information under PIPEDA means any information about an identifiable individual, which includes everything from employee records to customer databases to the contents of a retired laptop’s hard drive. There is no carve-out that limits protection to sensitive categories; if the data identifies a person, it’s covered.

PIPEDA’s 10 fair information principles include safeguards (Principle 7) and accountability (Principle 1), and both bear directly on device retirement. Safeguards require that personal information be protected by security measures appropriate to the sensitivity of the data, and that protection extends through the entire lifecycle, including disposal. Accountability requires that an organization designate someone responsible for compliance and be able to demonstrate that its practices meet the standard.

The honest limitation is that PIPEDA’s destruction language is principle-based rather than prescriptive. The law doesn’t specify a destruction method, a documentation format, or a retention period for destruction records. It says personal information that is no longer required to fulfill the purposes for which it was collected should be destroyed, erased, or made anonymous. In practice, that means the organization has to build its own destruction protocol and be prepared to defend it to the Office of the Privacy Commissioner if a complaint arises. The flexibility is real, but so is the exposure when an organization can’t produce records showing what was done.

PHIPA Scope and What It Demands When Devices Leave

The Personal Health Information Protection Act is Ontario provincial legislation. It governs the collection, use, disclosure, retention, and disposal of personal health information by health information custodians. The threshold question isn’t whether an organization handles health data; it’s whether the organization qualifies as a health information custodian under the Act.

Health information custodians include physicians, hospitals, pharmacies, long-term care facilities, community health centres, and certain other health-related entities defined in the statute. The definition is role-based rather than industry-based, which means a technology company building health software doesn’t automatically become a custodian just because it processes health records.

Personal health information under PHIPA is more narrowly defined than personal information under PIPEDA. It covers information that identifies an individual and relates to their physical or mental health, the provision of health care, a plan of service, payments or eligibility for health care, donation of body parts, or the individual’s health number. Data on a retired drive that falls outside these categories may not be PHIPA-covered even if the organization is a custodian.

PHIPA’s destruction obligations are more specific than PIPEDA’s. A custodian that disposes of personal health information must do so in a secure manner, and the Act requires custodians to retain records of that disposal. The Ontario Information and Privacy Commissioner has issued guidance reinforcing that custodians should be able to demonstrate what was destroyed, when, and by what method. Other provinces have analogous health privacy statutes, including Alberta’s Health Information Act and Manitoba’s Personal Health Information Act, so organizations outside Ontario should identify their own provincial equivalent rather than assuming PHIPA applies nationally.

The Custodian Threshold Most Organizations Miss

This is where the comparison between PIPEDA vs PHIPA creates the most confusion at device retirement. A private-sector company that develops electronic medical records software, operates a telehealth platform, or provides IT services to a hospital handles personal health information every day, but handling health data doesn’t make an organization a health information custodian under PHIPA. The custodian designation belongs to the health-care provider or facility, not necessarily to the vendor processing data on its behalf.

An organization that isn’t a custodian but receives personal health information from one is typically classified as an agent of the custodian under PHIPA. Agents have obligations, but the compliance framework is different, and the custodian retains primary accountability. Meanwhile, that same organization’s commercial activities, including the data on its own corporate drives, may fall squarely under PIPEDA.

The practical consequence at device retirement is significant. A health technology company that builds its destruction protocol around PHIPA requirements alone may be satisfying obligations it doesn’t actually owe while neglecting the PIPEDA obligations it does. When drives leave the building, the question isn’t just what data is on them; it’s what legal role the organization plays with respect to that data, and the answer may be different for different drives in the same batch.

When Both Laws Apply to the Same Organization

An Ontario health information custodian that also conducts commercial activity can owe obligations under both PHIPA and PIPEDA simultaneously. A physician’s office, for example, is a custodian under PHIPA for patient records but may also collect personal information through commercial activities like marketing or vendor relationships that fall under PIPEDA.

Ontario’s PHIPA has been deemed substantially similar to PIPEDA by the federal government, which means that for activities covered by PHIPA, the federal law generally steps back. The substantially similar designation applies only to the activities within PHIPA’s scope, so commercial activities outside the custodian’s health information role remain subject to PIPEDA. The distinction matters when retiring devices because a single server may contain both patient health records governed by PHIPA and business records governed by PIPEDA, and the destruction documentation needs to account for both.

In edge cases, the interaction between the two laws isn’t always settled. An organization that processes health data for multiple custodians while also running its own commercial operations may find that the line between PHIPA-covered and PIPEDA-covered data on a given drive is genuinely unclear. Where that ambiguity exists, the safer practice is to document destruction to the more specific standard and retain records that satisfy both frameworks.

Enforcement Differences That Change How You Document Destruction

PHIPA is enforced by the Ontario Information and Privacy Commissioner, which has targeted authority over health information custodians. The IPC can initiate reviews, conduct inspections, and order compliance. Penalties under PHIPA can include fines for individuals and organizations that wilfully violate the Act. The enforcement posture is sector-specific, which means a custodian’s destruction practices are more likely to face scrutiny tailored to health data handling.

PIPEDA is enforced by the federal Office of the Privacy Commissioner, which operates primarily on a complaint-driven model. The OPC investigates complaints, conducts audits, and issues findings, but its enforcement tools have historically been less prescriptive than the IPC’s. The OPC can refer matters to the Federal Court for binding orders, but the process is slower and less targeted than provincial health privacy enforcement.

This asymmetry should shape how organizations document destruction. A health information custodian facing potential IPC review needs granular records: what was destroyed, the method used, the date, and who performed or supervised the destruction. An organization subject only to PIPEDA has more latitude in format but still needs records sufficient to demonstrate that its safeguards principle was met. In both cases, the documentation outlives the drive, and the absence of records is itself a compliance failure.

A Note on HIPAA for Canadian Organizations

HIPAA is United States legislation. It has no direct jurisdiction over Canadian organizations operating in Canada. The question a Canadian organization should ask is whether it handles data belonging to US patients or works as a business associate of a US covered entity. If the answer is yes, HIPAA obligations may apply to that specific data relationship, but they don’t replace or modify the organization’s Canadian obligations under PIPEDA or PHIPA. For device retirement purposes, the governing law for drives containing only Canadian data is always Canadian.

Verdicts by Organization Type at Device Retirement

A private-sector business with no health data falls under PIPEDA. Destruction documentation should record the method, date, and responsible party, built to the safeguards principle standard. A health information custodian in Ontario falls under PHIPA for patient health information, with PIPEDA potentially applying to non-custodian commercial activities on the same devices. Documentation should meet the IPC’s more specific expectations.

A private health technology company that doesn’t qualify as a custodian is governed by PIPEDA, not PHIPA, even though the data it handles may be health-related. And an organization unsure of its custodian status needs legal review before building a destruction protocol, because the answer is unsettled without it.

Across all four scenarios, organizations retiring working devices have a practical option worth considering. Electronics recycling through a reuse-first model, where functioning equipment is refurbished and donated to charities and community groups, can reduce the volume of drives requiring physical destruction. Organizations exploring responsible electronics donation programs should confirm that their chosen partner provides data sanitization records sufficient for the applicable legal framework.

Choosing a Retirement Path That Supports Your Compliance Record

Regardless of whether PIPEDA vs PHIPA governs the data on a particular drive, every organization retiring devices should have the same core documentation in hand: a record of what was destroyed or sanitized, by what method, on what date, and by whom. Working devices donated through a reuse program rather than destroyed still require a data sanitization record, because the compliance obligation follows the data, not the device’s destination.

Organizations looking to give working technology a second life while maintaining their compliance posture can explore options through the Electronics Recycling Association, a Canadian non-profit dedicated to reducing electronic waste through refurbishment and community donation. Whether devices are destined for reuse or responsible recycling, the documentation your partner provides is what closes the compliance loop. Confirm that it covers the right law before the drives leave your building.