Rules

How Canadian privacy law shapes dental marketing under PIPEDA and PHIPA

Dental marketing Canada PIPEDA rules mean consent, limited use and breach duties apply to every patient list, with Ontario's PHIPA adding stricter terms.

What to take away

  • Dental marketing Canada PIPEDA rules set the floor: identify purposes, get meaningful consent, and use patient data only for what you told them.
  • Ontario practices face the stricter provincial layer under PHIPA, which governs health information held by custodians such as dental offices.
  • Marketing and care are different purposes. Consent for treatment does not automatically cover a newsletter, a review request or an ad audience.
  • Privacy compliance is documented, not assumed: a consent log, a retention schedule and a breach process are the working parts.
  • Access requests and breach reporting carry deadlines, and the Office of the Privacy Commissioner of Canada is the federal regulator for PIPEDA.
  • Provincial rules vary. Alberta, British Columbia and Quebec each have their own health privacy statutes, so check your province before copying an Ontario policy.

How PIPEDA sets the baseline for dental marketing consent in Canada

PIPEDA is the federal private-sector privacy statute. It applies to personal information a dental practice collects, uses or discloses in the course of commercial activity, which includes running a practice and promoting it.

The Office of the Privacy Commissioner of Canada oversees it and publishes the ground rules practices work from. The core obligations that shape dental marketing consent and patient data handling are set out in the federal guidance on PIPEDA obligations that shape dental marketing.

For a dental office, the practical reading is short. You need a purpose for every piece of patient information you hold. You need consent for that purpose. You need to limit collection to what the purpose requires.

A recall reminder, a treatment follow-up and a hygiene appointment booking all sit close to care. A promotional email about whitening, a paid social audience built from your patient list and a review request sit closer to marketing. The second group needs its own consent and its own explanation.

PIPEDA is not the only federal statute in play. The Canadian Anti-Spam Legislation governs commercial electronic messages, so a marketing email needs both a privacy basis and a CASL basis. Those are separate tests, and passing one does not pass the other.

Provincial law can override PIPEDA where a province has substantially similar legislation. That is why an Ontario practice works primarily from PHIPA and a practice in Alberta works from its own health information statute. The federal guidance on privacy laws in Canada explains how the federal and provincial layers fit together.

One more Canadian wrinkle: language. A practice marketing to patients in Quebec has to account for Bill 96 and the Charter of the French Language, which affect how consent notices and marketing materials are drafted and displayed. Privacy consent that a patient cannot read is not meaningful consent.

The ten fair information principles applied to a dental patient list

The ten fair information principles are the substance of PIPEDA, not a preamble. The Commissioner's summary of the PIPEDA fair information principles is the version most practices should work from.

Here is what each one asks of a dental marketing list.

Principle What it means for a patient list
Accountability Someone in the practice owns privacy, by name, not by committee
Identifying purposes The consent form states the marketing purpose before collection
Consent Marketing consent is separate from treatment consent
Limiting collection Collect only what the marketing purpose needs
Limiting use, disclosure, retention No secondary use, no list sales, and a deletion date
Accuracy Contact details and preferences are kept current
Safeguards The list is access-controlled and encrypted
Openness A plain-language privacy policy is published
Individual access A patient can see what you hold about them
Challenging compliance A named route for complaints and a response process

Accountability is where most small practices fail first. A privacy officer who exists only on paper does not satisfy the principle. The person needs the authority to stop a campaign.

Identifying purposes and consent work together. If your intake form says information is used "to provide dental care," a promotional campaign falls outside that purpose. Add a separate, optional marketing line with its own checkbox.

Limiting use, disclosure and retention is the principle that catches list rentals, purchased lists and data appended from third parties. Buying a list of local residents and mailing them is a disclosure problem and a CASL problem at the same time.

Safeguards matter more than they used to. A patient list sitting in a spreadsheet shared by link, or a marketing platform with weak access controls, is a breach waiting for a trigger. The same discipline applies to the tracking scripts that ad and analytics tools drop onto booking pages.

The cost of dental marketing canada often includes the tools that carry this risk.

Where Ontario's PHIPA adds stricter rules for dental practices

PHIPA is Ontario's health privacy statute. It applies to health information custodians, a category that includes dental offices, and it governs personal health information in any format, paper or electronic.

The PHIPA statutory text on e-Laws Ontario is worth reading directly, especially the definitions of health information and custodian, rather than relying on a summary.

PHIPA is stricter than PIPEDA in a few ways that matter to marketing. It sets out rules for collection, use and disclosure that are purpose-specific, and it limits disclosure to purposes the statute permits or the patient consents to.

It also imposes duties around electronic records, including notification duties when personal health information is stolen, lost or accessed without authority. That obligation attaches to the custodian, which is the practice, not the marketing vendor.

Marketing sits awkwardly under PHIPA because most of it is not a health care purpose. Promotional communication about services is generally not a permitted use without consent, so the practice needs a clear consent basis or a de-identified approach.

De-identification is a real option, but only if it is done properly. Removing names while keeping a full postal code, a birth date and a treatment history does not de-identify anyone in a small town.

Ontario practices should also note that the Royal College of Dental Surgeons of Ontario sets advertising and record-keeping expectations through its own guidance. Privacy compliance and professional compliance are separate files that both need attention.

Other provinces are not identical. Alberta's Health Information Act and British Columbia's Personal Information Protection Act each have their own consent and access rules. Quebec's Law 25 added significant privacy obligations on top of its existing framework. A template policy copied across provinces will not hold.

Consent, use and disclosure: what changes between marketing and care

Consent in a dental practice is usually bundled. The intake form is signed once, and everything from treatment to billing to reminders is covered by a single signature.

That model works for care and fails for marketing. Marketing consent should be separate, optional, and refusable without any effect on treatment.

Use is what the practice does with information internally. Disclosure is what it hands to someone else, including a marketing agency, an email platform, an analytics provider or an ad network.

A vendor that receives a patient list is a disclosure, even if the vendor is Canadian and even if the contract says the data stays in Canada. The practice remains accountable for what the vendor does with it.

This is where Canadian practices diverge from their American counterparts. A US practice works within HIPAA and its business associate agreements. Canadian practices work within PIPEDA or a provincial health statute, and the vendor contract has to reflect that.

The US side is covered in this guide to HIPAA-compliant dental marketing, but the Canadian obligations are the ones that bind you.

Consent can be express or implied depending on the sensitivity of the information and the reasonable expectations of the patient. Marketing to a patient about a service related to their own care is a different case from marketing a cosmetic package to the whole list.

Withdrawal has to be as easy as giving consent. If a patient can opt in through a form but can only opt out by phone during business hours, the process is not equivalent.

Email marketing deserves its own note. A dental newsletter needs a working unsubscribe, accurate sender identification and a mailing address, and it needs to respect the consent basis you recorded. The practical requirements are set out in this piece on what a dental practice marketing budget should cover to protect that consent.

Health information, genetics and biometrics: dental data in scope

Dental records are health information. That sounds obvious, but marketing teams often treat a patient list as a contact database rather than a health record, and the distinction changes what is allowed.

A list that includes treatment history, insurance details or clinical notes is health information. Even a bare list of patients is personal information linked to a health service, which raises the sensitivity level.

The Commissioner publishes guidance on health information, genetics and biometrics that covers how sensitive health data should be handled. The sensitivity principle matters: the more sensitive the information, the higher the bar for consent.

Genetics enters dental marketing in a narrow but real way. Some practices offer genetic testing or carry results from a referring physician. Genetic information is treated as highly sensitive, and using it to target a marketing campaign is not a defensible purpose.

Biometrics enters through clinical imaging and identity tools. Intraoral scans, facial photographs and 3D imaging are patient data. Using them in before-and-after advertising requires consent that specifically covers marketing use, not just treatment.

Photographs are the most common flashpoint. A patient may consent to a clinical photo for their file and object to it appearing on the practice website or social channels. Those are different purposes and need different consent.

Northern and remote practices face an added consideration. Small populations mean de-identification is harder, and a case study with a recognizable detail can identify a patient in a community of a few hundred people.

A dental marketing privacy compliance checklist for Canadian practices

Work through this list before the next campaign. Each item maps to an obligation in PIPEDA, PHIPA or both.

  • Name a privacy officer with authority to halt a campaign
  • Separate marketing consent from treatment consent on the intake form
  • Record the date, method and scope of every marketing consent
  • Publish a plain-language privacy policy on the practice website
  • List every vendor that touches patient data, with a written agreement
  • Confirm where each vendor stores data and who can access it
  • Set a retention and deletion schedule for the marketing list
  • Provide a working unsubscribe and honour withdrawals promptly
  • Document the breach response process and who reports what
  • Review consent language after any new service or campaign launch
  • Check whether your province has its own health privacy statute
  • Confirm French-language requirements if you market in Quebec

The vendor inventory is the item most practices skip. Every email platform, booking tool, review service, CRM and ad network that receives patient data belongs on that list.

Consent records should survive staff turnover. If the person who collected consent leaves and the record is in their inbox, the practice cannot demonstrate consent when asked.

Retention deserves a number. Keeping a marketing list indefinitely because deletion is inconvenient is a retention failure, and it enlarges the impact of any breach.

Review the checklist when something changes: a new service line, a new agency, a new province, a new booking tool. Privacy compliance is a maintenance task, not a one-time project.

Record-keeping, access requests and breach duties under PIPEDA

PIPEDA gives patients the right to access the personal information a practice holds about them and to ask for corrections. A request can cover marketing records, not just clinical files.

The practice has to respond within the timeframe set by the statute and can only refuse on limited grounds. A refusal needs a reason and a route to challenge it.

Record-keeping supports all of this. If you cannot produce the consent record, the practical answer to a complaint is that consent cannot be demonstrated.

Breach duties require a real process. A breach of security safeguards involving personal information triggers assessment and, where there is a real risk of significant harm, reporting to the Commissioner and notification to affected individuals. Records of every breach must be kept.

Marketing vendors are the usual source of trouble, because a compromised email platform or ad account can expose a patient list without the practice knowing immediately. Contracts should require prompt notification and specify who reports.

Access requests and breaches are also reputational events. Handling them quickly and plainly is cheaper than handling them after a complaint reaches a regulator.

The questions patients and staff actually ask about privacy tend to overlap with broader common dental marketing strategy questions and dental content marketing, so keep answers consistent across channels.

Common questions

Does PIPEDA apply to a dental practice in Ontario? PHIPA governs health information in Ontario and is the primary statute for dental offices there. PIPEDA can still apply to personal information outside PHIPA's scope, such as some employment or commercial records.

Can I email my patient list about a new service? Only with a consent basis that covers marketing, plus compliance with the Canadian Anti-Spam Legislation. Treatment consent does not cover promotional email.

Do I need consent to use before-and-after photos? Yes. Marketing use is a separate purpose from clinical record-keeping, and the consent should say so explicitly, including where the image will appear.

What happens if a marketing vendor suffers a breach? The practice remains accountable as the custodian or organization. Assess the risk of significant harm, report where required, notify affected patients, and keep a record.

How long can I keep a marketing list? Keep it only as long as the marketing purpose requires, then delete it. Set a defined retention period and follow it rather than keeping the list indefinitely.

Do the rules differ in Alberta, British Columbia or Quebec? Yes. Each has its own health or private-sector privacy statute, and Quebec adds language requirements. Check your provincial rules before reusing a policy written elsewhere.

More in Rules

Rules

How Quebec dental practices meet Bill 96 French-language rules

Bill 96 dental marketing Quebec: what the OQLF expects of your practice website, ads and signage, and the changes to make before the 2027 deadline.

Rules

What CASL consent rules require of Canadian dental email newsletters?

CASL dental email marketing runs on express or implied consent, ten-business-day unsubscribe handling, and records that stand up to penalties.

Latest from Records Desk