Your prospects have rights before they even apply
Privacy compliance does not start at enrolment. It starts at first contact. The moment a prospect shares their email address, name or phone number — via a form, a chatbot, an education fair or an open house — the institution becomes accountable for that personal information under PIPEDA and applicable provincial privacy legislation (Source: Office of the Privacy Commissioner of Canada (OPC) guidance on accountability, updated 2025).
This matters because admissions and marketing teams process prospect data long before any formal application. And prospect data is often the least protected data in the entire information system: Excel files shared by email, contact lists exported from fairs without documented consent, chatbot conversations stored without a retention policy.
62% of institutions surveyed have no documented procedure for processing prospect data (Source: Skolbot survey of 62 marketing directors across North American and European institutions, December 2025). This operational guide addresses that gap.
For a broader overview of data protection compliance in higher education, see our complete guide to student data protection.
The Canadian privacy landscape: federal and provincial layers
Unlike countries with a single national data protection law, Canada operates a layered system that admissions teams must navigate carefully.
PIPEDA: the federal baseline
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to all private-sector organizations that collect, use, or disclose personal information in the course of commercial activities. For private universities and colleges engaged in marketing and recruitment, PIPEDA sets the baseline. It is built on 10 fair information principles, with consent and accountability at the core.
Quebec: Loi 25 — the strictest provincial law
Quebec's Loi 25 (Act to modernize legislative provisions respecting the protection of personal information), which came into full effect in September 2024, is the most stringent privacy law in Canada. It requires privacy impact assessments for any information system handling personal data, a designated privacy officer, explicit consent for each purpose, and the right to data portability. Quebec-based institutions — and any institution recruiting Quebec prospects — must comply.
Alberta and British Columbia: substantially similar legislation
Alberta's Personal Information Protection Act (PIPA) and British Columbia's equivalent PIPA are deemed "substantially similar" to PIPEDA. Institutions operating in these provinces follow provincial law rather than PIPEDA for intra-provincial activities. The practical differences are minor but real — Alberta's PIPA, for example, requires mandatory breach notification with specific timelines.
Public institutions: FIPPA considerations
Public universities and colleges in most provinces fall under freedom of information and protection of privacy legislation (FIPPA or equivalent) rather than PIPEDA. However, the principles — consent, purpose limitation, data minimization — largely overlap. Marketing and recruitment activities at public institutions still require careful compliance.
Consent: the foundation of lawful collection
PIPEDA requires meaningful consent for every collection, use, and disclosure of personal information. In the context of student recruitment, consent must meet four criteria.
The four tests for valid consent
Knowledge and understanding: the prospect must understand what they are consenting to. Privacy notices must be written in plain language, not legal boilerplate. The OPC's guidance on obtaining meaningful consent emphasizes that information must be provided in a manner that is "readily available" and "easy to understand."
Freedom of choice: consent cannot be a condition for receiving basic information. Making marketing consent mandatory to download a viewbook is not valid consent.
Specificity: one consent per purpose. A blanket "I agree to all communications" checkbox does not meet the standard. Separate consent for email nurturing, event invitations, and third-party sharing.
Active affirmation: pre-ticked boxes and implied opt-in do not constitute valid express consent for commercial electronic messages. Under CASL, express consent requires a clear affirmative action.
Common mistake: collecting emails at an education fair via a tablet with a simple "Leave your email for more info" does not constitute valid consent under PIPEDA or CASL.
Implied consent: limited and time-bound
PIPEDA recognizes implied consent in narrow circumstances — for example, when a prospect's inquiry creates a reasonable expectation that follow-up communication is appropriate. Under CASL, implied consent from an inquiry expires after 6 months if no commercial relationship is established. Relying on implied consent for ongoing marketing campaigns is risky.
What you collect — and what you should not
The principle of data minimization
PIPEDA's limiting collection principle requires that only information necessary for the identified purpose be collected. In practice, every form field must be justifiable.
Data necessary for an information request: first name, surname, email, program of interest. Four fields suffice.
Questionable data: date of birth (why do you need this before an application?), postal address (are you really sending printed viewbooks?), phone number (will you actually call?).
Problematic data: citizenship status (unless relevant for international admissions or tuition classification), Indigenous status, family situation, parental income. These are sometimes collected "just in case" but represent a privacy risk without documented justification.
Each additional form field reduces the completion rate by 5-8% (Source: Skolbot analysis of 45 institution contact forms, 2025). Data minimization is not just a legal obligation — it is a conversion lever. Our article on school website conversion benchmarks confirms this correlation.
Data collected by chatbots
A chatbot collects more data than a form. Prospects spontaneously share sensitive information (disabilities, financial difficulties, health conditions). Three measures are essential: prior notice that the conversation is recorded, automatic purging of sensitive data, and restricted access to conversation histories. In Quebec, Loi 25 requires a privacy impact assessment before deploying any technology that processes personal information.
Retention periods: the grey zone
Retention is the weakest point for most institutions. The OPC recommends that personal information should be retained only as long as necessary to fulfill the identified purposes — in practice, no more than 2 to 3 years after the last active contact (Source: OPC retention guidance). But this recommendation is a ceiling, not a target.
Recommended retention periods by data type
First-contact data (form, chat): 12 months after the last contact if the prospect has not applied. Beyond that, the study project is most likely abandoned.
Incomplete application data: 24 months after the last contact. The prospect may apply in the following cycle.
Rejected application data: 6 months after notification of rejection. Retaining data longer has no operational justification.
Chatbot conversations: 12 months, with automatic anonymization of sensitive data at 30 days.
Event data (open houses, fairs): 12 months after the event if the prospect has not taken further action.
The "keep everything" trap
47% of institutions retain prospect data indefinitely (Source: Skolbot survey, December 2025). This creates a double risk: regulatory (OPC enforcement actions and potential penalties under proposed federal privacy reform) and operational (degraded email deliverability, skewed metrics, increased attack surface). Under Quebec's Loi 25, the risk is more immediate — administrative monetary penalties of up to $25 million CAD or 4% of worldwide turnover apply.
Prospect rights: what your team must be able to answer
PIPEDA and provincial laws confer specific rights on individuals regarding their personal information. In practice, four are regularly exercised by student prospects.
Right of access: the prospect can request what data you hold. PIPEDA requires a response within 30 days. This means knowing where data is stored across all systems — CRM, chatbot, files, emails.
Right to correction: amendment of inaccurate data, propagated across all systems where the information resides.
Right to withdrawal of consent: a prospect can withdraw consent for any or all uses of their personal information at any time. Under CASL, unsubscribe requests must be honoured within 10 business days.
Right to challenge compliance: individuals can challenge an institution's compliance with PIPEDA by filing a complaint with the OPC. The OPC can investigate and make recommendations — and under proposed federal reforms, may gain order-making power.
Under Quebec's Loi 25, prospects also have the right to data portability — to receive their data in a structured, commonly used format and have it transferred to another organization.
The case of minors
In Canada, there is no single statutory age of digital consent — unlike some jurisdictions that set a fixed threshold. The OPC has indicated that consent from minors must be meaningful, which means the consent process must be appropriate to the minor's age and understanding. For prospects under 16, best practice is to obtain parental consent or use a two-tier consent model. Quebec's Loi 25 requires parental consent for minors under 14.
For pre-university outreach programs and social media campaigns targeting high school students, include an age verification step in your forms and have a parental consent pathway ready. This is particularly relevant for institutions running Grade 11 and Grade 12 recruitment activities.
Operational checklist for admissions teams
Data collection
- Every form displays required privacy information (identity of institution, purpose, retention period, contact for privacy inquiries)
- Consent checkboxes are not pre-ticked
- Consents are granular (one per purpose)
- The chatbot identifies itself as AI and informs users that conversations are recorded
- Fair and open house forms include privacy notices
- Only necessary data is collected (minimization principle)
- Privacy impact assessment completed for new systems processing personal data (required under Loi 25, best practice under PIPEDA)
Storage and access
- Prospect data is stored in a CRM with role-based access control
- No Excel files containing personal data are shared by email
- Data access is logged
- Sensitive data (disability, family situation) is isolated with restricted access
- CRM passwords meet OPC recommendations (12+ characters, MFA enabled)
- Data is stored on Canadian servers or in jurisdictions with adequate protection
Retention and purging
- A retention policy is documented and enforced
- Automatic purging is configured in the CRM
- Prospects with no interaction for 12 months are purged or enter a reactivation sequence before deletion
- Rejected application data is deleted at 6 months
- CASL implied consent expiry (6 months from inquiry) is tracked and enforced
Exercising rights
- A process for handling access, correction, and deletion requests is documented
- The admissions team knows who to contact internally to process a request
- The 30-day response deadline is tracked and met
- Marketing unsubscribes are processed within 10 business days (CASL requirement)
- A designated privacy officer is in place (required under Loi 25, recommended under PIPEDA)
The five most common privacy mistakes in admissions
Mistake 1: the fair spreadsheet. Collecting 200 emails at an education fair, emailing the file to yourself, then importing into the CRM without documented consent. Triple infringement — PIPEDA, CASL, and provincial law.
Mistake 2: opt-in by default. Pre-ticked "I agree to receive communications" checkbox. Invalid consent under both PIPEDA and CASL. Penalties under CASL reach up to $10 million CAD per violation for organizations.
Mistake 3: infinite retention. Prospect data from 2019 still in the CRM. Infringement of the limiting retention principle plus metrics skewed by dead contacts.
Mistake 4: late response. An access request circulating between three departments for three weeks. The 30-day PIPEDA deadline is breached. Under Loi 25, the default response period is also 30 days, with the possibility of a 10-day extension.
Mistake 5: the chatbot without notice. The chatbot collects name, email, program of interest without informing the user about the purposes of collection. Breach of the openness and transparency principles — and under Loi 25, a failure to obtain valid consent.
The trust dividend: beyond compliance
73% of 18-to-24-year-olds say that data protection influences their choice of institution (Source: cross-referenced findings from the EDUCAUSE Centre for Analysis and Research and Canadian surveys on student digital experience). Privacy compliance is not just a legal obligation — it is a professionalism signal that directly influences recruitment.
In a country where privacy is constitutionally protected and where public trust in institutions' handling of personal data is a recurring theme in OPC surveys, demonstrating strong data stewardship is a competitive advantage.



