Privacy in Practice
Canada’s Privacy Landscape with Commissioner Patricia Kosseim
September 15, 2026
In this episode of Privacy in Practice, Kellie du Preez and Danie Strachan speak with Patricia Kosseim, Information and Privacy Commissioner of Ontario, about how privacy law operates across Canada’s federal, provincial, territorial, and sector-specific regimes. They discuss the interaction between PIPEDA and provincial privacy laws, cross-jurisdiction regulatory cooperation, Ontario’s PHIPA framework for health information, and what regulators may expect organizations to demonstrate in practice. The conversation also examines constructive engagement with privacy regulators.
In this episode of Privacy in Practice, Kellie du Preez and Danie Strachan speak with Patricia Kosseim, Information and Privacy Commissioner of Ontario, about how Canada’s privacy laws and regulatory authorities operate in practice. Patricia explains the roles of federal, provincial, and territorial privacy commissioners, where their jurisdictions may overlap, and how PIPEDA interacts with provincial privacy laws deemed substantially similar. She also describes how regulators cooperate when investigations or breaches extend across jurisdictions.


The discussion then turns to Ontario’s Personal Health Information Protection Act (PHIPA), including how the law permits certain uses of personal health information for research and health-system purposes when its conditions are satisfied. Patricia discusses recurring gaps between written policies and actual implementation, the evidence regulators may ask organizations to produce, organizational responsibility for inappropriate access, and what can build or weaken credibility during proactive regulatory consultation. 


What This Episode Covers:


Patricia Kosseim is the Information and Privacy Commissioner of Ontario. Before taking on her current role, she spent more than a decade at the Office of the Privacy Commissioner of Canada as senior general counsel, where her work included national privacy policy, appearances before courts and Parliament, and engagement with regulators internationally. Her earlier experience included private practice advising organizations on responsible data governance and work in health research at the intersection of privacy, ethics, and innovation.


Connect with Patricia Kosseim here: LinkedIn
Connect with Kellie du Preez here: LinkedIn
Connect with Danie Strachan here: LinkedIn
Follow VeraSafe here: LinkedIn


If you enjoyed this episode, make sure to subscribe, rate, and review it.


Episode Highlights:


Patricia explains that Canada does not have one privacy law or one privacy commissioner. Federal, provincial, and territorial commissioners have their own mandates, with jurisdiction that can sometimes overlap or operate in parallel. She also discusses the long-standing cooperation among Canadian privacy regulators and the role courts have played in reinforcing privacy rights in Canada.

Patricia explains how PIPEDA applies to commercial activity and how its application changes where a province has privacy legislation deemed substantially similar. She discusses Quebec, Alberta, British Columbia, and Ontario’s distinct position under PHIPA, as well as situations in which organizations may fall under concurrent regulatory jurisdiction.

The discussion turns to Ontario’s health privacy law. Patricia describes PHIPA as an enabling statute that permits specified uses of personal health information, including for research and health-system purposes, subject to conditions. She uses research as an example to discuss research plans, ethics review, agreements, and the importance of maintaining those safeguards as projects change.


Patricia identifies recurring gaps between organizational policies and implementation. Examples include missed annual training, PIAs that were required but not completed, inconsistent software patching, available security controls that were not enabled, unimplemented audit recommendations, and information retained beyond intended periods. She explains what  her office may expect organizations to produce as evidence that their stated practices have actually been followed.

Patricia discusses the consultation function of her office and the circumstances in which organizations may approach a regulator proactively. She explains that credibility is strengthened when organizations engage early but have already assessed the privacy implications themselves, including through a PIA. Consultation undertaken largely to demonstrate that the regulator was contacted, without meaningful regard for its recommendations, can have the opposite effect.


Episode Resources:


Privacy in Practice is handcrafted by our friends over at: fame.so.

Connect with us at podcast@verasafe.com

This podcast is brought to you by VeraSafe.