Almost every Canadian small-business site I open has this backwards. There is a cookie banner bolted to the front — copied from a European template, sometimes rented monthly — and behind it no privacy policy at all. That is precisely the wrong way round. Canada does not require the banner. It does expect the policy.

I am a web designer, not a lawyer, so everything below is built on what the regulators themselves publish, and every claim links to the page it came from. What I can tell you first-hand is the mechanical half: what a contact form actually collects, which third-party scripts run before a visitor clicks anything, and what you are obliged to say about all of it.

Four things on an ordinary small-business website collect personal information. Most owners can name two.

The short version

  • PIPEDA applies to you. There is no revenue or headcount threshold — the test is whether you handle personal information commercially.
  • The legal root of "you need a privacy policy" is Principle 8, Openness: make your practices "publicly and readily available".
  • Canada has no blocking-banner rule. The Privacy Commissioner accepts opt-out consent for ad tracking — on conditions.
  • Run Google Analytics? You already agreed by contract to post a privacy policy. Section 7 of its terms says so plainly.
  • A form fill is implied consent for six months. A signed customer, two years. After that, marketing needs express consent.
  • CASL's ceiling is $1 million for an individual and $10 million for a business, per violation.
  • The software bill for doing this properly is $0. It costs an afternoon, not a subscription.

Does my website need a privacy policy in Canada?

Yes, if it collects anything — a contact form, analytics, a booking widget, even server logs. PIPEDA covers every organization handling personal information in the course of commercial activity, with no exemption for being small. Principle 8 requires you to make those practices "publicly and readily available", and a privacy page is how that is done.

Two details people get wrong. The first: there is no size cutoff. The law is not written around revenue or staff count, it is written around whether the activity is commercial, which a business website is by definition. The second: Ontario has no general private-sector privacy law of its own. Only Alberta, British Columbia and Quebec have their own, declared substantially similar to PIPEDA. Everywhere else, including Ontario, the federal law is the one that applies.

Notice what PIPEDA does not say. There is no clause instructing you to publish a page titled "Privacy Policy". What Principle 8 says is that "an organization must make detailed information about its policies and practices relating to the management of personal information publicly and readily available." A page in your footer is simply the cheapest way anyone has found to satisfy that sentence.

The four places your website collects personal information

Before you write a word of policy, find out what your own site is doing. Every small-business site I audit collects in the same four places, and three of them happen without the visitor doing anything.

Collection points on a typical small-business website
WhereWhat it takesWhat you owe the visitor
Contact or quote formName, email, phone, the message itselfSay why you are collecting it before they type, and use it only for that
AnalyticsIP, pages viewed, device, approximate cityName the vendor and say what the cookies are for
Advertising pixelsThe visit, and whether it turned into an enquiryName every platform — this is the one that needs real prominence
Server logsIP address, timestamp, page requestedSay your host keeps them, and roughly for how long

Principle 2 is the one that lands on the first row: "the purposes for which the personal information is being collected must be identified by the organization before or at the time of collection." That is a sentence beside your form, not a link at the bottom of the page. Principle 5 then closes the loop — information can only be used for the purpose it was collected for, which is the reason a quote request is not a newsletter signup.

The four places a small business website collects personal information: contact form, analytics, ad pixels and server logs

Here is my own, since I would rather show you a real one than describe an imaginary one. The page you are reading loads three third-party scripts: Google Tag Manager for Analytics, Cloudflare Turnstile on the contact form, and an OpenAI ads pixel. All three are named on my privacy policy, along with Stripe and my email host. Not because naming them looks thorough — because a policy that omits one of them is a written statement that is not true.

Do I need a cookie banner in Canada?

No — not the European kind. No Canadian law requires a visitor to click before a cookie may load. PIPEDA does require consent to collect personal information, but the Privacy Commissioner's published position is that opt-out consent can be appropriate for online behavioural advertising, provided the purpose is obvious and the visitor can actually decline.

The banner everyone copies exists to satisfy European rules, and it arrived in Canada by cultural transmission rather than by legislation. If you genuinely sell to people in the EU, that is a real conversation to have with a lawyer. If you install eavestroughs in Etobicoke, it is a pop-up that costs you mobile enquiries in exchange for nothing.

European cookie rules compared with Canadian expectations
The questionEU templateCanada
Blocking banner requiredYesNo
Consent before the cookie loadsYesNo
Opt-out consent accepted for ad trackingNoYes, on conditions
Purpose must be obvious, not buriedYesYes
Health and other sensitive dataExpress consentExpress consent
Comparison of EU cookie banner rules against Canadian privacy guidance on consent

The conditions are the interesting part, because they are stricter than the banner in one specific way. The OPC's policy position on online behavioural advertising says the purposes must be made obvious and "cannot be buried in a privacy policy". It also says that where a person has no viable way to decline the tracking — the examples given are zombie cookies, super cookies and device fingerprinting — an organization should not be using that technology for advertising at all. And it says an opt-out model is not appropriate for sensitive information such as health, which matters if you run a clinic site.

Canada does not ask you to interrupt the visitor. It asks you to be obvious. Only one of those costs you enquiries.

The rule that catches everyone: you already agreed to this

Suppose you decide the law is somebody else's problem. There is a second obligation sitting on almost every small-business site, and it is a contract rather than a statute, which means nobody argues about whether it applies to them.

Section 7 of the Google Analytics Terms of Service requires you to post a privacy policy, and that policy "must provide notice of Your use of cookies, identifiers for mobile devices ... or similar technology used to collect data." It goes further: you must disclose your use of Google Analytics and how it collects and processes data, which Google suggests you do with a prominent link to its own "How Google uses information from sites or apps that use our services" page.

So if you have the GA4 tag on your site — and you almost certainly do, because every web designer in the country installs it by reflex — you agreed to publish a privacy policy on the day it went in. One of these two obligations is a law with a regulator behind it. The other is a contract you clicked through, and the remedy for breaking a contract with Google is Google.

CASL: the part that reaches your contact form

CASL governs commercial email, not websites. But your website feeds it, which is where small businesses get into trouble. Someone who fills in your quote form gives you implied consent for six months. A customer who signed a contract gives you two years. Past that, marketing them needs express consent.

CASL consent types and how long each lasts
Type of consentHow you get itHow long it lasts
ExpressYou asked, in writing or verbally, and they agreedNo time limit until they withdraw it
Implied — purchase or contractThey bought from you or signed an agreementTwo years from that date
Implied — inquiryThey asked you something, e.g. your quote formSix months from that date

Two mechanical requirements travel with every commercial message regardless of which row you are in. You must identify yourself — business name, a current mailing address, plus a phone number, email or web address — and that contact information has to stay valid for at least 60 days after the message is sent. And you must provide an unsubscribe mechanism, honoured within 10 business days and at no cost to the recipient.

The ceiling for getting this wrong is $1 million per violation for an individual and $10 million for an organization. Real penalties are much smaller and weigh things like the nature of the violation and ability to pay, but I have yet to meet the business owner who wanted to explore the range personally.

The quote-reply exemption almost everyone gets half right

If a stranger asks you for a quote and you email them the quote, the consent requirement does not apply. Subsection 6(6)(a) of CASL exempts a message that solely "provides a quote or estimate for the supply of a product, goods, a service, land or an interest or right in land, if the quote or estimate was requested by the person to whom the message is sent."

Half right, because of two words people skip. The exemption lifts paragraph 6(1)(a) — consent — and nothing else. Identification and unsubscribe stay exactly where they were. And the message has to solely provide the quote: the moment you append "while I have you, here is our newsletter", you are outside the exemption you were relying on.

In practice this is not a burden. Your business name, address and phone number belong in your email signature anyway, and "reply STOP and I won't follow up" is one line. It is the difference between a quote email that is compliant by accident and one that is compliant on purpose.

What actually goes on the page

Nine things. Write them in the order a person would ask them, in the language you would use on the phone.

  1. Who you are — legal or operating name, a real mailing address, and a way to reach a human.
  2. Every category you collect, and why — the "why" beside each one, not in a separate paragraph. This is Principle 2 doing its job.
  3. What is collected automatically — analytics, pixels and server logs, each named by vendor.
  4. Cookies — what they are used for here, and how somebody refuses them.
  5. Who else sees it — every processor by name: email host, payment provider, hosting company, ad platforms.
  6. Where it is stored — and if any of it leaves Canada, say so rather than hoping nobody asks.
  7. How long you keep it — an actual number per category. "As long as necessary" is not an answer, it is a shrug.
  8. How to get a copy, a correction or a deletion — which address to email, and how fast you will respond.
  9. That they can complain to the Privacy Commissioner if your answer does not satisfy them.

Mine runs about 900 words and took an afternoon. Copy the structure from it if it helps — but write your own sentences, because the sentences have to describe your business. A borrowed policy is a document that is inaccurate on purpose, which is a worse position than having none at all.

What this should cost you

Nothing, in software. Consent-management subscriptions are sold hard to Canadian businesses, and the question to ask before buying one is which Canadian rule it satisfies. Generated policy pages have the same problem from the other end: a page that names no vendors, no retention periods and no address fails every one of the nine items above, whatever it cost to produce.

What it genuinely costs is an afternoon of writing down what your site actually does, and that work is unavoidable because only you know your suppliers. The two situations where I would pay a lawyer rather than read a regulator's website: you handle health information or children's data, or you really do sell into the EU. Everything else on a normal small-business website is a writing job, and you can see what a full build including the policy pages costs on my pricing page.

The twenty-minute audit

  1. Open your own site in a private window and list every form on it, including the newsletter box in the footer and any booking widget.
  2. View the page source and search for googletagmanager, facebook, hotjar, and any script loading from a domain that is not yours. Write down every one you find.
  3. Ask your host how long server logs are kept. They will know, and the answer should be a fixed number of days rather than "forever".
  4. Write the nine sections above in plain English, naming everything from steps 1 and 2.
  5. Link it from the footer of every page, not only the homepage. "Readily available" means readily.
  6. Put one sentence beside your contact form saying what you will do with the message.

Step six is the one everybody skips, and it is the one that actually satisfies Principle 2 — the purpose has to be identified before or at the time of collection, and a link in the footer is neither. One sentence does it: "I'll use this to reply to you and nothing else" answers the question people are silently asking before they type their phone number. If you are rebuilding those forms anyway, it belongs in the same pass as how you capture the lead in the first place.

⚖️

One honest limit. I build websites; I do not practise law. Everything above links to the regulator or the statute it came from, and that is deliberate — read the source before you make a decision that matters. If your business handles health records, financial data or anything about children, this guide is where you start the conversation with a lawyer, not where you end it. The same principle applies to AODA and accessibility compliance, which is a separate obligation with its own deadlines.

Frequently asked questions

Does a small business website need a privacy policy in Canada?+

Yes, if it collects anything at all — a contact form, analytics, a booking widget or even server logs. PIPEDA applies to every organization that handles personal information in the course of commercial activity, and it has no revenue or headcount threshold. Principle 8 requires you to make your handling practices publicly and readily available, and a privacy page is how that is normally done.

Do I need a cookie banner on a Canadian website?+

No Canadian law requires a visitor to click something before a cookie may load. The Privacy Commissioner accepts opt-out consent for online behavioural advertising, provided the purpose is obvious and understandable and, in the OPC's own words, is not buried in a privacy policy. If you genuinely sell to people in the EU, that is a separate conversation about EU law.

Can I copy a privacy policy from another website?+

No, and this is the one shortcut that actively makes things worse. A privacy policy is a written statement about what your business does with personal information. Copying someone else's gives you a document that is inaccurate on purpose, which is harder to defend than having nothing. Copy the structure; write the sentences about your own site.

Does PIPEDA apply to Ontario businesses?+

Yes. Ontario has no general private-sector privacy law of its own — only a health-specific one — so PIPEDA is the law that covers an Ontario business collecting personal information commercially. Alberta, British Columbia and Quebec have their own private-sector laws that the federal government has declared substantially similar.

Can I add people who filled in my contact form to my newsletter?+

Not indefinitely. Under CASL an inquiry or application gives you implied consent for six months, and a purchase or written contract gives you two years. Beyond that you need express consent. PIPEDA points the same way through Principle 5: information collected to answer a question should be used to answer that question.

What are the penalties under CASL?+

The maximum administrative monetary penalty per violation is $1 million for an individual and $10 million for an organization. The amounts actually issued are far smaller and depend on factors such as the nature of the violation, any history of violations and ability to pay — but the ceiling is not decorative.

Do I need a privacy policy if I only use Google Analytics?+

Yes, and in that case you have agreed to it twice. Section 7 of the Google Analytics Terms of Service requires you to post a privacy policy that gives notice of your use of cookies and device identifiers, and to disclose your use of Google Analytics and how it collects and processes data. That obligation is contractual and does not care how small you are.

Sources, read in full on 16 September 2026: Office of the Privacy Commissioner — PIPEDA in brief for who the law covers and which provinces have substantially similar legislation; OPC — the ten fair information principles for the quoted wording of Principles 2, 5 and 8; OPC — policy position on online behavioural advertising for opt-out consent and the "cannot be buried in a privacy policy" condition; Justice Laws — CASL, subsections 6(6) and 10(9)–(10) for the quote exemption and the two-year and six-month clocks; ISED — getting consent to send email and the CRTC's CASL material for the 60-day and 10-business-day requirements and the $1M/$10M maximum penalties; Google Analytics Terms of Service, section 7 for the contractual privacy-policy obligation. The third-party scripts described on this page are the ones this site actually loads, listed on my own privacy policy.

Not sure what your site is quietly collecting?

Send me the address and I will tell you which scripts run on it, what your forms take, and what your policy page is missing — in plain English, no invoice attached.

Get My Free Quote
Liubomyr Lukaniuk, SEO and web designer in Toronto
Liubomyr Lukaniuk Senior Web Designer · Toronto & the GTA

10+ years building websites for GTA trades, clinics and service businesses — including the policy pages and form wording nobody enjoys writing. Read my full bio · Get in touch