How Far Can a Canadian Employer Go? Employee Privacy and Workplace Monitoring in Canada
Canadian employers can monitor staff, but not without limits. Here's where the line actually sits across PIPEDA, Quebec's Law 25, and Ontario's monitoring rule, and how to stay on the right side of it.
By Valdra Team
A manager at a mid-sized Ontario firm once told me, with total sincerity, that because the laptops belonged to the company, he could read anything on them. Personal Gmail open in a browser tab. WhatsApp messages on a phone connected to the office Wi-Fi. Webcam snapshots every ten minutes to "confirm presence." His logic was simple: our equipment, our rules.
He was wrong, and wrong in a way that could have cost his company a complaint to the Office of the Privacy Commissioner and a very awkward afternoon with a labour arbitrator. Owning the device is not the same as owning the human using it. That gap, between what employers assume they can do and what the law actually permits, is where most workplace privacy trouble begins.
The myth of unlimited employer rights
Start with an uncomfortable truth for federally regulated employers: PIPEDA applies to your employees' personal information. Banks, telecoms, airlines, interprovincial transport, anything under federal jurisdiction handles employee data under the same framework that governs customer data. For the rest of the private sector in most provinces, employee information sits in a greyer zone, shaped by common-law privacy torts, employment standards, and arbitral jurisprudence rather than a single statute.
That greyness is not a free-for-all. Canadian courts and arbitrators have built a remarkably consistent test over the past two decades, and it almost always comes down to one question: was the monitoring reasonable? Reasonableness has structure. Adjudicators ask whether the surveillance addressed a real, demonstrated problem, whether it was the least intrusive option available, whether employees knew about it, and whether the benefit to the employer outweighed the loss of privacy to the worker.
The OPC has published guidance that reinforces exactly this. Continuous video pointed at workers, GPS tracking that keeps running after hours, keystroke logging that scoops up passwords and personal messages: these get struck down not because monitoring is forbidden, but because the employer reached for a sledgehammer when a clear policy and the occasional spot-check would have done the job.
Quebec changed the math
Employ anyone in Quebec and the analysis shifts hard. The Commission d'accès à l'information (CAI) treats employee personal information as fully protected, and Law 25 (formerly Bill 64) tightened the screws considerably as its provisions rolled out from 2022 through 2024.
Under Law 25 you need a designated person responsible for protecting personal information. You owe employees transparency about what you collect and why. And here is the clause that bites: any technology used to identify, locate, or profile an individual must be disclosed to that person before it is activated. It reads as though it were written with workplace surveillance in mind. Quietly installing tracking software on a Quebec employee's phone, or switching on location services in a fleet vehicle without telling the driver, is now a direct violation.
The penalties are not theoretical. Law 25 allows administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is greater, and penal fines that can reach $25 million or 4% of worldwide turnover. Quebec also created a private right of action, so an aggrieved employee can sue for damages, with punitive damages available where the breach was intentional or grossly negligent. No other province has put that kind of financial weight behind employee privacy.
Ontario wrote it down
Ontario took a quieter route. Through amendments to the Employment Standards Act, 2000, an employer that has 25 or more employees on January 1 of a given year must put a written electronic monitoring policy in place by March 1 of that year. The policy has to state whether the employer monitors employees electronically and, if it does, how and in what circumstances, and what the collected information will be used for.
Be clear about what this law does and does not do. It does not limit monitoring. An Ontario employer can still watch a great deal; the statute simply forces disclosure. There is no new right to complain to a regulator about excessive surveillance, and no private cause of action attached to the policy requirement itself. The Information and Privacy Commissioner of Ontario (IPC) oversees public-sector and health-sector privacy, but the electronic monitoring rule lives under employment standards and is enforced by the Ministry of Labour.
So a worker who reads the policy and hates it has thin recourse under this particular law. The real effect is evidentiary. If you disclosed the monitoring and the employee kept working, you stand on much firmer ground in any later dispute. Skip the policy and you are not only offside the ESA, you have handed a future arbitrator a reason to doubt your good faith.
Where BYOD breaks everything
Bring-your-own-device is where the cleanest legal theories fall apart. The employee owns the phone. The employer owns some of the data on it. Mobile device management (MDM) software can wipe the whole device, read its location, enforce passcodes, and in aggressive configurations inspect installed apps and network traffic.
The expectation of privacy on a personal phone runs high. The Supreme Court of Canada pointed in that direction in *R. v. Cole*, 2012 SCC 53, a case about a work-issued laptop where the Court found a reasonable, though diminished, privacy interest in personal data, precisely because personal use of the device had been permitted. Flip the ownership to the employee and that interest only grows.
A few practices keep employers out of trouble:
- Containerize, don't surveil. Wall corporate data off in a managed container so a remote wipe touches company information only, never the employee's photos, messages, or banking apps.
- Disclose the full capability of the MDM. If the software *can* see location or browsing, say so, even if you promise never to look. Quebec law arguably requires it; everywhere else it is the line between defensible and indefensible.
- Get genuine, informed consent. A clause buried in an onboarding PDF that nobody reads will not survive scrutiny. And because an employee who fears for their job cannot truly refuse, consent is a weak foundation on its own. Reasonableness still has to carry the weight.
The honest read is that BYOD trades a small hardware saving for a large privacy liability. Many of the cleaner-run organizations I work with hand out a cheap dedicated work phone for exactly that reason, so the ownership question never gets murky.
The standard that governs employee privacy workplace monitoring Canada relies on
Strip away the provincial variation and a careful employer can hold to four habits that satisfy nearly every Canadian adjudicator.
Tie the monitoring to a real purpose. "We want to make sure nobody slacks off" is not a purpose a tribunal respects. "We had three confirmed thefts from the loading dock last quarter" is. Collect the minimum: if attendance is the concern, a badge swipe answers it without a webcam in someone's home office. Tell people, in writing, before you start, in plain language, naming the specific tools. Then review what you collected only for the stated reason and dispose of it on a schedule instead of hoarding logs forever.
Surveillance that is secret is almost always surveillance that is excessive. The act of hiding it is itself evidence that it would not survive daylight.
That is close to how arbitrators actually reason. Covert monitoring is permitted in narrow circumstances, usually a serious and specific suspicion of wrongdoing that cannot be investigated any other way, but it is the exception that proves how heavily the system favours transparency.
What this means for a small Canadian business
Most employers reading this are not banks with a privacy department. They are a 40-person company with a worried owner, an HR generalist wearing four hats, and a patchwork of provinces the moment anyone works remotely. The compliance burden feels confusing because it genuinely is fragmented: federal rules for some staff, CAI rules for your Montreal hire, an ESA policy for your Ontario team, and common law for everyone else.
You do not need a $500,000 consultant to map this. You need to know which laws touch your specific workforce, what each one demands, and where your current practices fall short. That assessment is concrete and finite, and it is exactly the kind of work software can do faster and cheaper than a billable-hour firm. To see which employee-privacy obligations apply to your business and what to fix first, run a privacy assessment built for Canadian employers.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra