Compliance
PHIA vs PIPEDA: which privacy law applies to your Nova Scotia business
Nova Scotia businesses can fall under a federal privacy law, a provincial health-information law, or both. Here is who each one covers, where they overlap, and the practical obligations for a small business.
You run a business in Nova Scotia, you collect personal information about customers, and somewhere along the way someone told you that you need to “be compliant.” Compliant with what, exactly. There are two privacy laws people tend to mix up here, they cover different things, and a single business can be on the hook for both at once. Sorting out which applies to you is the first step, and it is not as complicated as it sounds.
A note before we start: this is a plain-language overview to help you understand the landscape, not legal advice. Privacy law turns on specifics — what information you hold, why, and who you share it with — and the edge cases genuinely need a professional. Treat this as the map that helps you ask better questions.
Two laws, two kinds of information
The confusion comes from the fact that the two laws are organized around different ideas.
PIPEDA — the federal Personal Information Protection and Electronic Documents Act — is about personal information collected in the course of commercial activity. It is a general-purpose, private-sector privacy law. Nova Scotia does not have its own general private-sector privacy statute the way British Columbia, Alberta, and Quebec do, so for most ordinary commercial handling of personal information by a Nova Scotia business, the federal law is the one that governs.
PHIA — Nova Scotia’s Personal Health Information Act — is about one specific, sensitive category: personal health information. It applies to organizations and individuals the Act calls “custodians,” who hold health information in the course of providing care or a related service. It is provincial, and it is narrower and, in places, stricter than the general rules, because health information is treated as especially sensitive.
The short version: PIPEDA is the broad commercial default; PHIA is the specific health-information layer that sits on top for the businesses it touches.
Who PIPEDA covers
If your business collects, uses, or discloses personal information — names, contact details, purchase history, account records, anything that identifies a person — as part of doing business, assume PIPEDA is in the picture. That covers the large majority of Nova Scotia companies: the shop with a customer list, the trades business with client records, the software company storing user accounts, the marketing firm holding email subscribers.
“Personal information” is broad. It is not just financial or sensitive data; it is any information about an identifiable individual. An email address tied to a name counts.
Who PHIA covers
PHIA applies to “custodians” of personal health information. The clearest examples are the obvious ones: doctors, dentists, pharmacists, physiotherapists, clinics, and other regulated health professionals and facilities. If your core work is delivering health care, you are almost certainly a custodian and PHIA governs the health records you keep.
Where it gets less obvious is at the edges. A business that is not itself a health provider might still handle personal health information — for example, a company providing services to a clinic, or an employer holding certain health-related records. Whether PHIA reaches a given arrangement depends on the details, and this is precisely the kind of question worth putting to a lawyer or a privacy advisor rather than guessing. The cost of asking is small; the cost of assuming wrong can be large.
Where they overlap
A single business can be subject to both, applied to different data.
Picture a physiotherapy clinic. The clinical records — assessments, treatment notes, health histories — are personal health information under PHIA. But the same clinic also runs a business: it markets to prospective clients, keeps an email list, processes payments, and manages staff. That general commercial personal information can fall under PIPEDA. Two laws, one organization, two categories of information, each with its own rules.
This is why “which law applies to me” is often the wrong question. The better question is “which law applies to this information,” asked one dataset at a time.
The practical obligations, in plain terms
Both laws rest on a similar spine of principles, even where the details differ. For a small business, the practical obligations tend to come down to a handful of habits.
- Collect with a purpose, and be able to say what it is. Collect what you actually need, for a reason you can state, and generally with the person’s knowledge and consent. Health information under PHIA carries a higher bar for consent and a tighter view of what counts as a legitimate use.
- Use it only for what you collected it for. Information gathered for one purpose should not quietly get repurposed for another without going back for consent.
- Safeguard it. Both laws expect reasonable security appropriate to the sensitivity of the information — access controls, encryption where warranted, staff who know the rules, and a way to keep unauthorized people out. Health information, being more sensitive, warrants stronger safeguards.
- Let people see their own information. Individuals generally have a right to access the personal information you hold about them and to ask for corrections. Health custodians have specific processes for this under PHIA.
- Have a plan for a breach. Under PIPEDA, breaches posing a real risk of significant harm must be reported to the federal Privacy Commissioner and affected individuals, and records of breaches must be kept. PHIA has its own breach-notification expectations for health information. Either way, “we will figure it out if it happens” is not a plan; the plan needs to exist before the incident.
- Be accountable. Name someone responsible for privacy, write down your practices, and be able to show your reasoning. Regulators respond very differently to a business that took privacy seriously and made a mistake than to one that never thought about it.
None of this requires an enterprise compliance department. For most small businesses it is a matter of a few clear policies, sensible technical controls, and someone whose job it is to keep them current.
When to get real advice
Get professional advice when the answer actually matters and the facts are not obvious: when you are unsure whether you are a PHIA custodian, when you are about to share personal information with a vendor or a partner, when you are moving records to a new system or a cloud provider, when you handle health information in any non-obvious way, or when you have had a breach. A lawyer or a qualified privacy consultant will save you far more than they cost in those moments.
Where we help is the technical side — the safeguards, the access controls, the auditability, and the systems that make good privacy practice the default rather than a constant effort. That work sits alongside the broader security posture we wrote about in our guide to PIPEDA compliance for Atlantic Canada businesses, and it is a normal part of the IT work we do for businesses across Atlantic Canada.
Send us two paragraphs about the personal information your business holds and where it lives, and we will reply in writing within one business day.