{"id":160947,"date":"2026-09-02T10:15:18","date_gmt":"2026-09-02T07:15:18","guid":{"rendered":"https:\/\/ondato.com\/?p=160947"},"modified":"2026-09-02T10:15:20","modified_gmt":"2026-09-02T07:15:20","slug":"pipeda-compliance","status":"publish","type":"post","link":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/","title":{"rendered":"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A customer uploads a photo of their passport to open a bank account. But the bank\u2019s verification provider stores the image overseas. Months later, a former bank employee still has access to the image, and no one can explain why the data was retained.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is the kind of privacy gap the&nbsp;<strong>Personal Information Protection and Electronic Documents Act (PIPEDA)<\/strong> is designed to address. When businesses enter or operate in Canada, their compliance reaches far beyond having a privacy policy. It defines how they collect personal information, verify identities, manage vendors, secure data, and respond when something goes wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the scale of the risk is significant. In 2025-2026, the&nbsp;<a href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/ar_index\/202526\/ar_202526\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Office of the Privacy Commissioner of Canada<\/a>&nbsp;(OPC) received&nbsp;<strong>696 breach reports<\/strong>&nbsp;from businesses affecting more than 20 million Canadians, as well as&nbsp;<strong>3,044 PIPEDA complaints<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide explains who PIPEDA applies to, its core requirements, how it affects identity verification, and the practical steps businesses can take to build a compliant privacy program.<\/p>\n\n\n\n<h2 id=\"h-what-is-pipeda\" class=\"wp-block-heading\">What is PIPEDA? <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>PIPEDA<\/strong>&nbsp;is Canada\u2019s federal private-sector privacy law, governing how organizations collect, use, and disclose personal information during commercial activities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Personal information broadly means information about an identifiable individual. Depending on the context, that can include a name, contact details, account information, financial data, an IP address, an identity document, a photograph, or a biometric identifier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In line with\u00a0<a href=\"https:\/\/laws-lois.justice.gc.ca\/eng\/acts\/p-8.6\/FullText.html\">PIPEDA<\/a>, businesses may collect, use, or disclose personal information only for purposes that\u00a0a reasonable person would consider appropriate in the circumstances. Organizations must also follow ten fair information principles covering accountability, purposes, consent, collection, use and retention, accuracy, safeguards, openness, access, and complaints.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA also plays an important international role. For example, the&nbsp;<a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/international-dimension-data-protection\/adequacy-decisions_en\">European Commission<\/a>&nbsp;continues to recognize Canada as providing an adequate level of data protection for transfers to&nbsp;commercial organizations subject to PIPEDA. This makes the Canadian framework relevant to companies managing data across both Canadian and European markets.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of August 2026, PIPEDA remains Canada\u2019s current federal private-sector privacy law. The federal government has introduced <a href=\"https:\/\/www.parl.ca\/legisinfo\/en\/bill\/45-1\/c-36\">Bill C-36<\/a>, which would replace PIPEDA\u2019s private-sector provisions with the proposed Protecting Privacy and Consumer Data Act if the bill is enacted and brought into force.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that businesses operating in Canada should comply with PIPEDA now and continue to monitor the legislation.&nbsp;<\/p>\n\n\n\n<h2 id=\"h-whom-do-pipeda-requirements-apply-to-nbsp\" class=\"wp-block-heading\">Whom Do PIPEDA Requirements Apply To?&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA applies broadly to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Private-sector organizations<\/strong>&nbsp;across Canada that engage in commercial activities. For example, e-commerce companies and retailers to tech start-ups and professional services.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Federally regulated works, undertakings, and businesses<\/strong>&nbsp;(FWUBs) such as banks, airlines, railways, and telecommunications providers. These industries fall directly under federal jurisdiction, making PIPEDA their primary privacy law. Within these businesses, employee personal information collected for employment purposes is also covered.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Charities and non-profits<\/strong>&nbsp;that engage in commercial activities, such as selling merchandise, running membership programs, or offering paid services. Even if their mission is not profit-driven, their data-handling practices may still trigger PIPEDA.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Certain exclusions exist. For example, PIPEDA does not apply to data collected for personal or domestic purposes, such as a home address book or family photo album. Information collected, used, or disclosed by federal government organizations is also regulated under the Privacy Act, not PIPEDA.<\/p>\n\n\n\n<h2 id=\"h-does-pipeda-apply-to-your-business\" class=\"wp-block-heading\"><strong>Does PIPEDA Apply to Your Business?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA can apply sooner than many businesses expect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your organization collects, uses, or discloses personal information as part of a commercial activity in Canada, you may be in scope, even if privacy is not your core business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You may also need to comply if your company is based outside Canada. A foreign business without a Canadian office can still fall under PIPEDA when it has a \u201creal and substantial connection\u201d to Canada.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To qualify, your business may be involved in targeting Canadian customers, collecting their information, or sending data to and from Canada.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>EXAMPLE:<\/strong>&nbsp;A European online platform advertises to Canadian users, collects their identity documents during onboarding, and stores the information on servers in Europe. Its overseas headquarters do not automatically exclude it from PIPEDA requirements. If the business serves Canadians and handles their personal information, Canadian privacy obligations may still apply.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/r_o_p\/prov-pipeda\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Provincial rules<\/a>&nbsp;can change, though. &nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Alberta, British Columbia, and Quebec&nbsp;<\/strong>have general private-sector privacy laws that are considered substantially similar to PIPEDA.&nbsp;If your organization operates entirely within one of those provinces, the provincial law will often apply instead.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia<\/strong>&nbsp;also have substantially similar laws for certain personal health information.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">That does not mean PIPEDA disappears from the picture. It can still apply to federally regulated businesses and to personal information that crosses provincial or national borders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, a single customer journey may involve both federal and provincial requirements. So, it is worth mapping where your business operates, where your customers are located, and where their data travels.<\/p>\n\n\n\n<h2 id=\"h-pipeda-compliance-requirements\" class=\"wp-block-heading\">PIPEDA Compliance Requirements<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-1-1024x576.webp\" alt=\"PIPEDA requirements \" class=\"wp-image-160951\" srcset=\"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-1-1024x576.webp 1024w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-1-300x169.webp 300w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-1-768x432.webp 768w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-1.webp 1340w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA\u2019s principles become much easier to manage when translated into practical business actions. Here are&nbsp;<a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/airports-and-borders\/gl_dab_090127\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">key recommendations<\/a>&nbsp;and actions you should follow to ensure PIPEDA compliance.<\/p>\n\n\n\n<h3 id=\"h-make-someone-accountable-for-privacy\" class=\"wp-block-heading\">Make Someone Accountable for Privacy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You should assign responsibility for PIPEDA compliance to a specific person or a team. That person should oversee privacy policies, employee training, complaints, vendor controls, retention rules, and incident response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accountability also follows the information. If a third-party processor handles customer information on your behalf, your organization remains responsible for protecting it.<\/p>\n\n\n\n<h3 id=\"h-define-your-purpose-before-collecting-data\" class=\"wp-block-heading\">Define Your Purpose Before Collecting Data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before you collect any information, you should know&nbsp;why&nbsp;each category of personal information is needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an online service needs a customer\u2019s date of birth to confirm eligibility, that does not automatically justify collecting their occupation, full employment history, or unrelated device information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/laws-lois.justice.gc.ca\/eng\/acts\/p-8.6\/FullText.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PIPEDA specifically requires<\/a>&nbsp;collection to be limited to what is necessary for the identified purposes.<\/p>\n\n\n\n<h3 id=\"h-obtain-meaningful-consent\" class=\"wp-block-heading\">Obtain Meaningful Consent<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">People need to understand what they are agreeing to. That\u2019s why the OPC says organizations should clearly highlight four things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>what personal information is being collected<\/li>\n\n\n\n<li>why it is being collected, used, or disclosed<\/li>\n\n\n\n<li>who it will be shared with<\/li>\n\n\n\n<li>significant risks or consequences<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For sensitive information or unexpected processing,&nbsp;<a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-for-businesses\/appropriate-handling-of-personal-information\/collecting-personal-information-and-consent\/consent\/gl_omc_201805\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">expressed consent<\/a>&nbsp;will generally be appropriate. It\u2019s important to note that privacy information should be understandable at the point of decision, not hidden inside a long legal document.&nbsp;<\/p>\n\n\n\n<h3 id=\"h-control-use-disclosure-and-retention\" class=\"wp-block-heading\">Control Use, Disclosure, and Retention<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not quietly repurpose customer information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If data was collected for&nbsp;<a href=\"https:\/\/ondato.com\/blog\/what-is-identity-verification\/\" target=\"_blank\" rel=\"noreferrer noopener\">identity verification<\/a>, using the same information later for an unrelated advertising profile may require new consent and may not be an appropriate purpose at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also, you should create documented retention periods. Personal information should only be retained for as long as necessary for its identified purpose or applicable legal obligations, after which it should be securely deleted, destroyed, or anonymized.<\/p>\n\n\n\n<h3 id=\"h-keep-information-accurate-and-give-people-access\" class=\"wp-block-heading\">Keep Information Accurate and Give People Access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anywhere the collected information is used to make decisions about customers, it should be sufficiently accurate and up to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/p_principle\/\">Individuals also have the right<\/a>&nbsp;(subject to limited exceptions) to ask whether an organization holds their personal information, to understand how it has been used or disclosed, to obtain access to it, and to challenge inaccuracies.<\/p>\n\n\n\n<h3 id=\"h-apply-appropriate-security-safeguards\" class=\"wp-block-heading\">Apply Appropriate Security Safeguards<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Security should match the sensitivity of the information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A mailing-list email address and a&nbsp;<a href=\"https:\/\/ondato.com\/blog\/benefits-of-biometric-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">biometric identity<\/a>&nbsp;template do not carry the same level of risk. More sensitive information, therefore, should receive stronger technical, organizational, and physical safeguards, such as appropriate encryption, access controls, monitoring, employee permissions, and secure deletion.<\/p>\n\n\n\n<h3 id=\"h-be-transparent-and-provide-a-complaint-process\" class=\"wp-block-heading\">Be Transparent and Provide a Complaint Process<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Customers should be able to easily find information about your privacy practices and know who to contact with questions or complaints.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Moreover, your published privacy notice should match what actually happens inside your systems. If you add new providers, purposes, or technologies, review whether your notices and consent mechanisms also need updating.<\/p>\n\n\n\n<h2 id=\"h-practical-steps-to-pipeda-compliance\" class=\"wp-block-heading\">Practical Steps to PIPEDA Compliance<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-2-1024x576.webp\" alt=\"PIPEDA Compliance Steps\nMap your data \nDetermine which Canadian laws apply\nConnect every data field to a purpose and retention rule\nReview customer-facing privacy flows\nReview security and vendors \nTest your program\n\" class=\"wp-image-160954\" srcset=\"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-2-1024x576.webp 1024w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-2-300x169.webp 300w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-2-768x432.webp 768w, https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Featured-2.webp 1340w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A workable compliance program can be built in six stages:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 1. Map your data<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Identify what personal information enters your organization, where it comes from, why it is needed, where it is stored, who can access it, and where it is transferred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 2. Determine which Canadian laws apply<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check PIPEDA, provincial legislation, sector-specific requirements, and whether any information moves across borders.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 3. Connect every data field to a purpose and retention rule<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your team cannot explain why a piece of personal information is needed, reconsider collecting it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 4. Review customer-facing privacy flows<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Update consent screens, privacy notices, withdrawal mechanisms, and access-request procedures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 5. Review security and vendors<\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Assess providers before sharing information and include appropriate privacy and security obligations in contracts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STEP 6. Test your program<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Train employees, rehearse breach response procedures, periodically review permissions and retention, and update your processes as products or regulations change.<\/p>\n\n\n\n<h2 id=\"h-pipeda-and-identity-verification\" class=\"wp-block-heading\">PIPEDA and Identity Verification<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ondato.com\/blog\/best-identity-verification-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">Identity verification<\/a>&nbsp;can involve some of the most sensitive information a business handles: passports, driver\u2019s licenses, addresses, birth dates, photographs, financial information, and biometric characteristics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That makes privacy-by-design particularly important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider a&nbsp;<a href=\"https:\/\/ondato.com\/blog\/digital-onboarding\/\" target=\"_blank\" rel=\"noreferrer noopener\">digital onboarding<\/a>&nbsp;flow that asks a customer to photograph their identity document. The business should know exactly which fields it needs, why it needs them, and whether the full image must be retained after verification. If the business only needs proof that verification succeeded, retaining every raw document indefinitely creates unnecessary privacy and security exposure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>NOTE:&nbsp;<\/strong>Biometric information deserves additional attention.&nbsp;The OPC has described&nbsp;<a href=\"https:\/\/ondato.com\/authentication-solutions\/biometric-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">biometric data<\/a>&nbsp;as sensitive in almost all circumstances because it is closely and often permanently connected to an individual.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Express consent will generally be expected where sensitive biometric information is collected on the basis of consent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s why, when designing or selecting an identity verification process, as a business, you should consider:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Can you collect less information and still complete the verification?<\/li>\n\n\n\n<li>Is the purpose clearly explained before the user submits an ID or biometric data?<\/li>\n\n\n\n<li>Are sensitive fields and images encrypted and tightly access-controlled?<\/li>\n\n\n\n<li>How long are raw documents, selfies, or biometric templates retained?<\/li>\n\n\n\n<li>Can information be deleted once the necessary legal or business retention period ends?<\/li>\n\n\n\n<li>Are third-party processors restricted from using the information for their own unrelated purposes?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Another important point to note is that&nbsp;<strong>using a third-party verification provider does&nbsp;not&nbsp;remove the organization\u2019s PIPEDA responsibilities<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, this means that PIPEDA allows information to be transferred to processors, including those outside Canada, but the transferring organization remains accountable and must use contractual or other measures to provide comparable protection. Customers should also receive appropriate transparency about&nbsp;<a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/airports-and-borders\/gl_dab_090127\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cross-border processing<\/a>.&nbsp;<\/p>\n\n\n\n<h2 id=\"h-data-breaches-enforcement-and-penalties\" class=\"wp-block-heading\">Data Breaches, Enforcement, and Penalties<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA requires every organization to keep records of&nbsp;all breaches of security safeguards, not only the most serious ones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to&nbsp;<a href=\"https:\/\/laws-lois.justice.gc.ca\/eng\/acts\/p-8.6\/FullText.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Canada\u2019s Department of Justice<\/a>, when a breach creates a&nbsp;real risk of significant harm, the organization must report it to the OPC and notify affected individuals&nbsp;as soon as feasible.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The assessment should consider both the sensitivity of the information and the probability that it has been or will be misused. Significant harm can include identity theft, financial loss, reputational damage, humiliation, or negative effects on credit records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/laws-lois.justice.gc.ca\/eng\/regulations\/SOR-2018-64\/FullText.html\">Breach records<\/a>&nbsp;must be retained for&nbsp;<strong>24 months<\/strong>&nbsp;after the organization determines that the breach occurred.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current PIPEDA does not give the OPC a general power to impose administrative fines. However, knowingly violating certain statutory obligations, including specific breach reporting and record-keeping requirements, or obstructing the Commissioner can result in fines of up to&nbsp;<strong>CAN $10,000<\/strong> on summary conviction or <strong>CAN $100,000<\/strong> for an indictable offense.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Federal Court can also order organizations to correct their practices, publish corrective actions, and pay damages to complainants, including damages for humiliation.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All this means that for businesses, the practical cost of a privacy failure can extend well beyond a statutory fine to incident response, customer remediation, litigation, contractual problems, and loss of trust.<\/p>\n\n\n\n<h2 id=\"h-pipeda-vs-gdpr\" class=\"wp-block-heading\">PIPEDA vs. GDPR<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Businesses familiar with the EU\u2019s GDPR will recognize many of PIPEDA\u2019s principles, but the two laws are not interchangeable.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Scope.<\/strong> PIPEDA primarily focuses on personal information handled during commercial activities, while the GDPR has a broader processing framework and its own extraterritorial rules.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Legal basis.<\/strong>&nbsp;PIPEDA is strongly centered on meaningful consent, subject to statutory exceptions.&nbsp;<a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/information-business-and-organisations\/legal-grounds-processing-data_en\">GDPR expressly provides six lawful grounds<\/a>&nbsp;for processing, including consent, contract, legal obligation, and legitimate interests.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Individual rights.<\/strong>&nbsp;PIPEDA provides important access and correction rights. GDPR includes additional explicit rights such as erasure and data portability.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Breach reporting.<\/strong>&nbsp;PIPEDA requires notification as soon as feasible when the breach reaches the \u201creal risk of significant harm\u201d threshold. GDPR generally requires supervisory-authority notification within&nbsp;<strong>72 hours<\/strong>&nbsp;when a personal data breach is likely to create a risk to individuals\u2019 rights and freedoms.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Penalties.<\/strong>&nbsp;The current PIPEDA enforcement regime is significantly different from GDPR\u2019s administrative fine framework. Companies operating under both regimes should build controls that satisfy each law rather than assuming GDPR compliance automatically equals PIPEDA compliance.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"h-pipeda-compliance-checklist\" class=\"wp-block-heading\">PIPEDA Compliance Checklist<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use this checklist as a starting point for reviewing your Canadian privacy program:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Determine whether PIPEDA, provincial privacy legislation, or both apply to your activities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Assign a person or team accountable for privacy compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Maintain an inventory of the personal information you collect and where it flows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Document a legitimate, appropriate purpose for every category of information collected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Collect only the personal information necessary for those purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Provide clear, meaningful consent and privacy information at appropriate points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Use express consent where required for sensitive or unexpected processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Set and enforce documented retention and secure deletion rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Give customers processes for accessing and correcting their information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Protect information with safeguards appropriate to its sensitivity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Conduct privacy and security due diligence on third-party processors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Put privacy, security, retention, and processing requirements into vendor contracts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Maintain a breach-response process that includes the PIPEDA risk assessment and notification rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Keep records of every security breach for at least 24 months.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Train employees who handle personal information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2611\ufe0f Review your privacy program when products, vendors, technologies, or changes to Canadian laws.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PIPEDA compliance is based on knowing what information a business collects, why it needs it, who can access it, and when it should be deleted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, it\u2019s advisable to build those habits (purpose limitation, transparency, data minimization, security, and accountability) into your everyday systems and processes. This way, your compliance becomes far more manageable. And, more importantly, your customers get a clear, respectful privacy experience and a stronger reason to trust your business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A customer uploads a photo of their passport to open a bank account. But the bank\u2019s verification provider stores the image overseas. Months later, a former bank employee still has access to the image, and no one can explain why the data was retained. That is the kind of privacy gap the&nbsp;Personal Information Protection and [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":160948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[12],"tags":[87],"class_list":["post-160947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-aml-compliance"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v28.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>PIPEDA Compliance Guide: Requirements &amp; Checklist | Ondato<\/title>\n<meta name=\"description\" content=\"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist\" \/>\n<meta property=\"og:description\" content=\"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Ondato\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/OndatoKYC\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-02T07:15:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T07:15:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_SoMe.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Zarema Plaksij\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@OndatoKYC\" \/>\n<meta name=\"twitter:site\" content=\"@OndatoKYC\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Zarema Plaksij\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/\"},\"author\":{\"name\":\"Zarema Plaksij\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#\\\/schema\\\/person\\\/4c1159cad95d7a0e83aa6447f4f575ee\"},\"headline\":\"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist\",\"datePublished\":\"2026-09-02T07:15:18+00:00\",\"dateModified\":\"2026-09-02T07:15:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/\"},\"wordCount\":2437,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/v02_2026-09_PIPEDA-Compliance_Cover.webp\",\"keywords\":[\"AML Compliance\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/\",\"url\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/\",\"name\":\"PIPEDA Compliance Guide: Requirements & Checklist | Ondato\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/v02_2026-09_PIPEDA-Compliance_Cover.webp\",\"datePublished\":\"2026-09-02T07:15:18+00:00\",\"dateModified\":\"2026-09-02T07:15:20+00:00\",\"description\":\"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#primaryimage\",\"url\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/v02_2026-09_PIPEDA-Compliance_Cover.webp\",\"contentUrl\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/v02_2026-09_PIPEDA-Compliance_Cover.webp\",\"width\":1340,\"height\":754,\"caption\":\"PIPEDA compliance\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/blog\\\/pipeda-compliance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/ondato.com\\\/fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#website\",\"url\":\"https:\\\/\\\/ondato.com\\\/fr\\\/\",\"name\":\"Ondato\",\"description\":\"complete and cost-effective compliance management suite\",\"publisher\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/ondato.com\\\/fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#organization\",\"name\":\"Ondato\",\"url\":\"https:\\\/\\\/ondato.com\\\/fr\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/v01_Profile-photo-1.png\",\"contentUrl\":\"https:\\\/\\\/ondato.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/v01_Profile-photo-1.png\",\"width\":1080,\"height\":1080,\"caption\":\"Ondato\"},\"image\":{\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/OndatoKYC\",\"https:\\\/\\\/x.com\\\/OndatoKYC\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/12576605\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC4eMJhSGAf5hRO4YxnzrFFw\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/ondato.com\\\/fr\\\/#\\\/schema\\\/person\\\/4c1159cad95d7a0e83aa6447f4f575ee\",\"name\":\"Zarema Plaksij\",\"description\":\"A professional editor and copywriter with 14+ years of experience, Zarema is head over heels for content marketing and all that storytelling jazz. She believes that B2B and tech content should never be boring, but rather captivating and even fun. Right now, she\u2019s on a mission to make KYC regulations and AML compliance sound sharp, human, and mercifully jargon-free.\",\"url\":\"https:\\\/\\\/ondato.com\\\/fr\\\/author\\\/zarema-plaksij\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"PIPEDA Compliance Guide: Requirements & Checklist | Ondato","description":"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/","og_locale":"fr_FR","og_type":"article","og_title":"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist","og_description":"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.","og_url":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/","og_site_name":"Ondato","article_publisher":"https:\/\/www.facebook.com\/OndatoKYC","article_published_time":"2026-09-02T07:15:18+00:00","article_modified_time":"2026-09-02T07:15:20+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_SoMe.png","type":"image\/png"}],"author":"Zarema Plaksij","twitter_card":"summary_large_image","twitter_creator":"@OndatoKYC","twitter_site":"@OndatoKYC","twitter_misc":{"Written by":"Zarema Plaksij","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#article","isPartOf":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/"},"author":{"name":"Zarema Plaksij","@id":"https:\/\/ondato.com\/fr\/#\/schema\/person\/4c1159cad95d7a0e83aa6447f4f575ee"},"headline":"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist","datePublished":"2026-09-02T07:15:18+00:00","dateModified":"2026-09-02T07:15:20+00:00","mainEntityOfPage":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/"},"wordCount":2437,"commentCount":0,"publisher":{"@id":"https:\/\/ondato.com\/fr\/#organization"},"image":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Cover.webp","keywords":["AML Compliance"],"articleSection":["Blog"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/","url":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/","name":"PIPEDA Compliance Guide: Requirements & Checklist | Ondato","isPartOf":{"@id":"https:\/\/ondato.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#primaryimage"},"image":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Cover.webp","datePublished":"2026-09-02T07:15:18+00:00","dateModified":"2026-09-02T07:15:20+00:00","description":"Learn how PIPEDA compliance works, who it applies to, key requirements, data protection obligations, and practical steps for businesses.","breadcrumb":{"@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#primaryimage","url":"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Cover.webp","contentUrl":"https:\/\/ondato.com\/wp-content\/uploads\/2026\/08\/v02_2026-09_PIPEDA-Compliance_Cover.webp","width":1340,"height":754,"caption":"PIPEDA compliance"},{"@type":"BreadcrumbList","@id":"https:\/\/ondato.com\/fr\/blog\/pipeda-compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/ondato.com\/fr\/"},{"@type":"ListItem","position":2,"name":"PIPEDA Compliance Guide: Requirements, Steps &amp; Checklist"}]},{"@type":"WebSite","@id":"https:\/\/ondato.com\/fr\/#website","url":"https:\/\/ondato.com\/fr\/","name":"Ondato","description":"complete and cost-effective compliance management suite","publisher":{"@id":"https:\/\/ondato.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ondato.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/ondato.com\/fr\/#organization","name":"Ondato","url":"https:\/\/ondato.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/ondato.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/ondato.com\/wp-content\/uploads\/2022\/08\/v01_Profile-photo-1.png","contentUrl":"https:\/\/ondato.com\/wp-content\/uploads\/2022\/08\/v01_Profile-photo-1.png","width":1080,"height":1080,"caption":"Ondato"},"image":{"@id":"https:\/\/ondato.com\/fr\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/OndatoKYC","https:\/\/x.com\/OndatoKYC","https:\/\/www.linkedin.com\/company\/12576605\/","https:\/\/www.youtube.com\/channel\/UC4eMJhSGAf5hRO4YxnzrFFw"]},{"@type":"Person","@id":"https:\/\/ondato.com\/fr\/#\/schema\/person\/4c1159cad95d7a0e83aa6447f4f575ee","name":"Zarema Plaksij","description":"A professional editor and copywriter with 14+ years of experience, Zarema is head over heels for content marketing and all that storytelling jazz. She believes that B2B and tech content should never be boring, but rather captivating and even fun. Right now, she\u2019s on a mission to make KYC regulations and AML compliance sound sharp, human, and mercifully jargon-free.","url":"https:\/\/ondato.com\/fr\/author\/zarema-plaksij\/"}]}},"_links":{"self":[{"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/posts\/160947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/comments?post=160947"}],"version-history":[{"count":5,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/posts\/160947\/revisions"}],"predecessor-version":[{"id":160975,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/posts\/160947\/revisions\/160975"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/media\/160948"}],"wp:attachment":[{"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/media?parent=160947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/categories?post=160947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ondato.com\/fr\/wp-json\/wp\/v2\/tags?post=160947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}