Browse by jurisdiction
Canada's federal private-sector privacy law based on 10 fair information principles. Requires express consent for sensitive data and implied consent for less sensitive data. OPC guidance addresses cookies and online behavioral advertising. The CPPA replacement bill died January 2025; a new bill is expected.
Quebec's Law 25 is the strictest privacy law in Canada and the closest North American equivalent to the GDPR. Consent must be clear, free, informed and requested for each purpose, and any technology that identifies, locates or profiles a visitor has to be disclosed. Its privacy-by-default rule carves out browser cookie settings, but non-essential cookies still need consent first.
COPPA is the primary US federal law protecting children's online privacy. It requires verifiable parental consent before collecting personal information from children under 13. Persistent identifiers including cookies are classified as personal information. The 2025 amendments expand protections significantly.
British Columbia's PIPA is recognized as substantially similar to PIPEDA. The OIPC can investigate complaints, conduct audits, issue binding orders, and require compliance. Nonprofits engaging in commercial activities are also covered. Organizations must destroy personal information once the original purpose is fulfilled.
Alberta's PIPA is recognized as substantially similar to PIPEDA, covering provincially regulated private-sector organizations. The OIPC has binding order-making power, stronger than PIPEDA's OPC which issues only recommendations. Express consent is required for sensitive data, implied for non-sensitive.
HIPAA protects health information privacy. OCR's 2022 guidance clarified that marketing pixels and tracking technologies on healthcare websites can constitute impermissible PHI disclosure. Cookie consent banners do NOT satisfy HIPAA authorization requirements. Enforcement now targets browser-based tracking.
GLBA requires financial institutions to explain information-sharing practices and give customers the right to opt out of sharing with certain third parties. The updated Safeguards Rule mandates comprehensive security programs. Most US state privacy laws exempt GLBA-regulated entities.
FERPA protects student education records at federally funded institutions. Written consent is required before disclosing personally identifiable information from education records. The sole enforcement mechanism is withdrawal of federal education funding, a penalty so severe it has never been imposed.