You run a Canadian business, so European privacy law is not your problem, right? Not always. The EU's General Data Protection Regulation, GDPR, was written to follow EU residents' data wherever it goes, which means it can apply to a Canadian company that has never set foot in Europe. For most purely local small businesses it does not, but if you sell online, run a SaaS product, or handle data from people in the EU, it is worth knowing where you stand. Here is the plain-language version. This is orientation, not legal advice.
When GDPR reaches across the ocean
GDPR can apply to your Canadian business in two main situations: if you offer goods or services to people in the EU (think an online store that ships there, or a service EU residents can sign up for), or if you monitor the behaviour of people in the EU (for example, tracking and profiling EU visitors to your website). The trigger is intent and reality, not a token possibility. A local cafe whose site happens to be reachable from Europe is not caught; a Canadian online shop that actively markets and sells to customers in Germany may well be.
How to tell if it is you
Ask a few honest questions. Do you deliberately sell to or market at people in the EU? Do you have EU customers or users whose personal data you collect? Do you track EU visitors for advertising or analytics in a meaningful way? If the answer is a clear no across the board, GDPR very likely does not apply, and your focus stays on Canadian rules like PIPEDA and Quebec's Law 25. If the answer is yes, it is worth taking seriously, because GDPR carries large penalties and its own set of obligations.
What it asks of you if it applies
- A lawful basis for using personal data, often consent, and clear, honest privacy information.
- Individual rights, including access, correction, and deletion, that you can actually respond to.
- Fast breach notification, generally within 72 hours to the relevant authority when required.
- Sensible data handling and, in some cases, an appointed EU representative or extra safeguards for transferring data out of the EU.
The good news for Canadian businesses
If you already run privacy well under Canadian law, get consent, keep only what you need, secure it, honour access and deletion requests, and can report a breach, you are most of the way to GDPR too, because the principles overlap heavily. The practical move is not panic but clarity: figure out honestly whether you are in scope, and if you genuinely sell into the EU or handle meaningful EU data, get a short professional review rather than guessing. Knowing you are out of scope is just as valuable as being ready if you are in it.