PIPEDA: What Your Website Actually Has to Do
Compliance · Published
If your website collects a name, an email address, a phone number or in many cases an IP address, Canada's federal privacy law applies to you. PIPEDA is not onerous for an ordinary small business, but it does require a few specific things that most small business websites do not have. This sets out what they are, in plain terms, and where the genuinely tricky parts sit. It is general information rather than legal advice, and anything consequential is worth putting to a lawyer.
Get a free quoteCall (613) 800-8028
What counts as personal information
Wider than most owners expect. Personal information is information about an identifiable individual, and the test is whether the person could reasonably be identified from it, alone or combined with other information you hold.
On a typical business website that captures: names, email addresses, phone numbers and postal addresses from forms; anything typed into a free-text message field; uploaded files; account details; and, in many circumstances, IP addresses, device identifiers and the cookies analytics and advertising tools set. The last group is the one businesses routinely fail to account for, because nobody thinks of an analytics script as collecting anything.
The ten principles, and the four you will actually trip over
PIPEDA is built on ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. For a small business website, four of them account for nearly every real gap.
- Identifying purposes. You have to say why you are collecting something, at or before the point you collect it. A contact form that asks for a phone number should be somewhere it is explained what the phone number will be used for.
- Consent. It has to be meaningful, which means the person understands what they are agreeing to. For anything sensitive, or any use a reasonable person would not expect, it has to be express rather than assumed from continued use of the site.
- Safeguards. Personal information has to be protected proportionately to its sensitivity. In website terms: HTTPS everywhere, form submissions that do not travel or sit in plain text, access limited to people who need it, and not leaving enquiries in a shared inbox that six people and a former employee can still read.
- Openness and access. Your practices have to be available in an understandable form, which is what the privacy policy is for, and an individual can ask what you hold about them and require you to correct it. You need to be able to answer that.
What a privacy policy actually has to contain
A generated policy naming a company you have never heard of is worse than none, because it is a public statement of practices you do not follow. The policy should describe what you actually do.
- What personal information you collect, including through analytics, advertising pixels and cookies.
- Why you collect each category, in specific terms rather than "to improve our services".
- How you use it, and whether you disclose it to anyone, naming the categories of third party. Analytics providers, email platforms, payment processors and booking systems all belong here.
- Where it is stored, and in particular whether it leaves Canada, which is very likely the moment you use an American analytics or email service. Cross-border transfer is permitted; not telling people about it is the problem.
- How long you keep it and what happens at the end of that period.
- How it is protected.
- How someone requests access to their information, or asks for a correction, with a real contact route.
- Who is accountable, with a way to reach them. PIPEDA requires a designated individual responsible for compliance.
- How to complain, and that they may escalate to the Office of the Privacy Commissioner of Canada.
Cookies, analytics and advertising pixels
This is where most Canadian small business sites are quietly offside, usually by inheriting a setup nobody documented. Canada does not have a cookie-banner rule equivalent to the European one, and the consent requirement still applies to the information those tools collect.
In practice: analytics that is limited, anonymised where possible, and disclosed in the policy sits comfortably. Advertising and remarketing pixels that build a profile of an individual across sites are a different proposition, and the expectation there is meaningful consent, obtained before the tracking starts rather than announced afterwards.
The workable approach for most businesses is a short, honest cookie notice that names the categories in use, links to the policy, and lets someone decline the non-essential ones. If you serve Quebec residents, the bar is higher and the technologies that collect personal information generally require consent by default.
Breaches, which is the part with hard deadlines
Since November 2018, a breach of security safeguards involving personal information must be reported to the Privacy Commissioner, and the affected individuals notified, if it creates a real risk of significant harm. Significant harm includes humiliation, damage to reputation or relationships, identity theft, fraud and financial loss. Reporting has to happen as soon as feasible.
Separately, and this is the requirement almost nobody knows about, you must keep a record of every breach of security safeguards for 24 months, including the ones that did not meet the reporting threshold. The Commissioner can ask for those records.
For a small business that means having somewhere to write it down and a named person who knows they are responsible for doing so. That is the whole obligation, and it takes an afternoon to set up.
If you serve Quebec or Gatineau clients
Quebec's private sector privacy law, substantially reformed by the legislation commonly called Law 25, is meaningfully stricter than PIPEDA and has been phasing in since 2022. It brings requirements around a designated privacy officer, privacy impact assessments in defined circumstances, explicit consent standards, mandatory breach reporting, and rights around data portability.
For an Ottawa business with Gatineau clients this is a real consideration rather than a theoretical one, and it is the clearest case on this page for getting advice specific to your situation rather than relying on a guide.
Where the law is going
Reform has been attempted and has not landed. A substantial federal package that would have replaced PIPEDA for the private sector did not survive the parliamentary cycle, which leaves PIPEDA in force with its existing structure and its comparatively modest enforcement powers.
The practical implication is not to wait. The things that would be required under a stricter regime, knowing what you collect, saying so plainly, holding less of it, and being able to answer an access request, are the same things PIPEDA already asks for and the same things a customer expects.
Related reading
- CASL: contact forms, newsletters and consent
- AODA and web accessibility for Ontario businesses
- The Ottawa small business website checklist
- Our website management service
- Ottawa web design pricing, published in full
- Ottawa web design by Shinobi Media
Frequently asked questions
Does PIPEDA apply to my small Ontario business?
Almost certainly yes. PIPEDA applies to organisations that collect, use or disclose personal information in the course of commercial activity, and there is no small-business exemption. Ontario has no general private-sector privacy law of its own, so the federal law is the one that applies. Quebec, British Columbia and Alberta have their own substantially similar laws covering businesses in those provinces.
Do I need a cookie banner in Canada?
Not in the specific form European law requires, but you do need meaningful consent for collecting personal information, and advertising and tracking technologies generally collect it. A short honest notice naming what is in use, with a way to decline the non-essential categories, meets the expectation for most businesses. Quebec's rules are stricter and should be treated separately.
Is an IP address personal information?
It can be, and the safe assumption is that it is. Canadian privacy regulators have treated IP addresses as personal information where they can be linked to an identifiable individual, alone or in combination with other data. Since that combination is exactly what analytics and advertising tools perform, treat them as in scope.
What happens if I ignore this?
The Privacy Commissioner can investigate complaints and publish findings, and matters can proceed to Federal Court, which can order damages. For a small business the practical risk is less a fine than a complaint that becomes public, a customer relationship lost over a breach handled badly, and the cost of sorting it out under pressure. The preventive work is an afternoon.
Can I just use a privacy policy generator?
As a starting structure, yes. As the finished article, no, because the policy has to describe what you actually do with information, and a generator cannot know that you email enquiries to a shared inbox and keep them forever. Start from a template, then make every sentence true.