CanucktAI
Compliance Library

30 compliance
frameworks, mapped

Every privacy, healthcare, financial, and AI regulation that applies to Canadian businesses — explained in plain language and automated by Valdra.

30Frameworks
6Categories
100%100% Canadian
FreeTo start

Showing 29 of 29 frameworks

Privacy
PIPEDA
Federal — Canada

Canada's federal private-sector privacy law

Office of the Privacy Commissioner of Canada (OPC)
Privacy
Law 25
Quebec, Canada

Quebec's sweeping privacy reform — Canada's strictest

Commission d'accès à l'information du Québec (CAI)
Privacy
CASL
Federal — Canada

Canada's anti-spam and electronic consent law

Canadian Radio-television and Telecommunications Commission (CRTC)
Privacy
PIPA (Alberta)
Alberta, Canada

Alberta's private-sector privacy law — substantially similar to PIPEDA

Office of the Information and Privacy Commissioner of Alberta (OIPC)
Privacy
PIPA (BC)
British Columbia, Canada

BC's private-sector privacy law — recognized as substantially similar to PIPEDA

Office of the Information and Privacy Commissioner for BC (OIPC BC)
Privacy
CPPA / Bill C-27
Federal — Canada (pending)

Canada's GDPR-equivalent — the biggest privacy law reform in 20 years

Office of the Privacy Commissioner of Canada + new Privacy Tribunal
Healthcare
PHIPA
Ontario, Canada

Ontario's health privacy law — governing all PHI custodians

Information and Privacy Commissioner of Ontario (IPC Ontario)
Healthcare
HIA (Alberta)
Alberta, Canada

Alberta's health privacy law for custodians and affiliates

Office of the Information and Privacy Commissioner of Alberta (OIPC)
Healthcare
HIIA (BC)
British Columbia, Canada

BC's modernized health data governance framework

Office of the Information and Privacy Commissioner for BC
Healthcare
PHIA (NS)
Nova Scotia, Canada

Nova Scotia's health privacy law for custodians of personal health information

Information and Privacy Commissioner for Nova Scotia (OIPC NS)
Healthcare
PHIPAA (NB)
New Brunswick, Canada

New Brunswick's combined health privacy and access law

Office of the Ombud — Access to Information and Privacy Commissioner (NB)
Healthcare
PHIA (NL)
Newfoundland & Labrador, Canada

Newfoundland & Labrador's health privacy law for custodians

Office of the Information and Privacy Commissioner (OIPC NL)
Healthcare
HIPA (SK)
Saskatchewan, Canada

Saskatchewan's health privacy law for trustees of health information

Saskatchewan Information and Privacy Commissioner (OIPC SK)
Healthcare
PHIA (MB)
Manitoba, Canada

Canada's first comprehensive health privacy law, governing Manitoba trustees

Manitoba Ombudsman
Financial
FINTRAC
Federal — Canada

Canada's AML/CFT compliance framework

Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Financial
OSFI B-10
Federal — Canada

Canada's federal financial institution technology risk framework

Office of the Superintendent of Financial Institutions (OSFI)
Financial
OSFI E-21
Federal — Canada

Operational risk and resilience for federally regulated financial institutions

Office of the Superintendent of Financial Institutions (OSFI)
AI Governance
EU AI Act
European Union (extraterritorial)

The world's first comprehensive AI law

European AI Office + national market-surveillance authorities
AI Governance
ISO 42001
International (ISO/IEC)

The certifiable AI management system standard

Accredited certification bodies
AI Governance
NIST AI RMF
United States (voluntary, used globally)

The voluntary US framework for trustworthy AI

U.S. National Institute of Standards and Technology
AI Governance
AIDA
Federal — Canada (pending)

Canada's first federal AI regulation law

AI and Data Commissioner (new office, pending)
AI Governance
Digital Charter
Federal — Canada

Canada's 10-principle framework for digital trust

Innovation, Science and Economic Development Canada (ISED)
Government
ATIA
Federal — Canada

Federal right of access to government information

Office of the Information Commissioner of Canada
Standards
ISO 27001
International (applies globally)

The international gold standard for information security

International Organization for Standardization (ISO)
Standards
ISO 27701
International (applies globally)

The privacy extension to ISO 27001 — mapping to PIPEDA and GDPR

International Organization for Standardization (ISO)
Standards
SOC 2 Type II
International (AICPA standard)

The SaaS security standard expected by every enterprise buyer

American Institute of CPAs (AICPA)
Standards
NIST CSF
International (US origin, globally adopted)

The cybersecurity risk framework adopted by Canadian enterprises and government

National Institute of Standards and Technology (NIST)
Standards
PCI DSS
International (applies to all merchants)

Mandatory security standard for every Canadian business that accepts cards

PCI Security Standards Council
Standards
GDPR Adequacy
European Union / Canada cross-border

The EU's recognition of Canada as a safe destination for EU personal data

European Commission / Office of the Privacy Commissioner

See which frameworks apply to you

Run a free Valdra assessment — a short guided questionnaire that gives you a scored gap analysis against every relevant Canadian framework.

Start free assessment

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

30 Compliance Frameworks Explained | Canuckt AI