Guide

PIPEDA privacy policy requirements for small business websites

Updated September 2026 · Canada · Privacy & PIPEDA

If your website collects names, email addresses, or any other personal information from visitors, Canadian law almost certainly requires you to have a privacy policy. The federal law is PIPEDA — the Personal Information Protection and Electronic Documents Act — and it sets out what your policy must explain. This guide walks through the requirements in plain English so your policy actually covers what the law demands.

Does PIPEDA apply to your business?

PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity. That covers most small business websites — contact forms, newsletter signups, online stores, and booking systems all count.

Three provinces have their own substantially similar laws: Alberta, British Columbia, and Quebec. If you operate only in one of those provinces, the provincial law applies instead — but the requirements are close enough that a good PIPEDA-style policy is the right starting point everywhere. Quebec's Law 25 is stricter in several areas, covered below.

The 10 fair information principles

PIPEDA is built on ten principles. Your privacy policy should reflect each one:

  • Accountability — someone in your business is responsible for privacy compliance.
  • Identifying purposes — you state why you collect personal information before or when you collect it.
  • Consent — you obtain meaningful consent for collection, use, and disclosure.
  • Limiting collection — you collect only what you need for the stated purposes.
  • Limiting use, disclosure, and retention — you use data only for those purposes and keep it only as long as necessary.
  • Accuracy — personal information is as accurate and up to date as needed.
  • Safeguards — you protect data with appropriate security measures.
  • Openness — your policies and practices are readily available to the public.
  • Individual access — people can request access to their information and challenge its accuracy.
  • Challenging compliance — people can complain to you and to the Privacy Commissioner of Canada.

What your policy must actually say

Translate the principles into concrete sections. At a minimum, your policy should identify your business, list the types of personal information you collect (contact details, account data, payment confirmations, technical data like IP addresses), explain why you collect each type, describe who you share it with (payment processors, hosting providers), state how long you keep it, and explain how visitors can access, correct, or delete their information.

It must also give a contact point for privacy questions. Vague statements like "we take privacy seriously" without specifics do not satisfy the openness principle.

Consent: the part most sites get wrong

PIPEDA requires meaningful consent — the person must understand what they are agreeing to. Pre-ticked checkboxes do not count. For sensitive information, or when the use goes beyond what a person would reasonably expect, you need express opt-in consent rather than implied consent.

Review every form on your site: does each one explain what the information is for, and does the visitor take a clear affirmative action? Newsletter signups, in particular, need an unchecked box or a double opt-in.

Cookies and tracking

Analytics tools, advertising pixels, and social media embeds all collect personal information under PIPEDA. Your policy should disclose what tracking technologies you use, what they collect, and how visitors can control them.

A cookie banner that just says "we use cookies" without linking to a real policy explaining the details is not meaningful consent. List the categories — necessary, analytics, marketing — and give visitors a genuine choice on the non-essential ones.

Quebec's Law 25: stricter rules

If you have customers in Quebec, Law 25 (the Act respecting the protection of personal information in the private sector) adds requirements: you must designate a person responsible for privacy, conduct privacy impact assessments for certain projects, notify the Commission d'accès à l'information and affected individuals of serious privacy incidents, and meet stricter consent and transparency rules.

Businesses operating across Canada typically write one policy that meets the highest standard — which increasingly means Law 25.

Keeping your policy current

A privacy policy is not a one-time document. Update it whenever you add a new tool, start collecting new data, or change how you use existing data — and tell your visitors when you do. PIPEDA's accountability principle means someone should own this: assign privacy responsibility to a named person, even in a one-person business.

Review the policy at least once a year, and keep a dated copy of each version so you can show what was in force at any given time.

Generate your privacy policy free

Answer a few questions about your business and get a PIPEDA-ready privacy policy, refund policy, and terms in minutes. Edit freely — pay only when you download.

Start my privacy policy

Free to draft and edit. $5 CAD one-time when you download.

This guide is general information about Canadian law, not legal advice. Laws change and every situation is different — have a licensed lawyer in your province review your document before you rely on it.